{
  "day": "2026-08-05",
  "boundary": "UTC calendar day",
  "published_count": 432,
  "by_severity": {
    "CRITICAL": 61,
    "HIGH": 203,
    "MEDIUM": 146,
    "LOW": 17
  },
  "kev_count": 1,
  "exploit_reference_count": 7,
  "awaiting_enrichment_count": 5,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-63077",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.10722,
      "epss_percentile": 0.95454,
      "kev": true,
      "kev_due_at": "2026-08-08",
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-502",
      "title": "JetBrains TeamCity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63077"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-18900",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02384,
      "epss_percentile": 0.82571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H3C",
      "product": "NX15",
      "cwe": "CWE-77",
      "title": "H3C NX15 Backend RPC esps file.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18900"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-18902",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02384,
      "epss_percentile": 0.82571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H3C",
      "product": "NX15",
      "cwe": "CWE-74",
      "title": "H3C NX15 esps repeaterproc command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18902"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-7693",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02233,
      "epss_percentile": 0.81363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inisev",
      "product": "Backup Migration",
      "cwe": "CWE-77",
      "title": "Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7693"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-71209",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0176,
      "epss_percentile": 0.76178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "advplyr",
      "product": "audiobookshelf",
      "cwe": "CWE-22",
      "title": "audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71209"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-66297",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0155,
      "epss_percentile": 0.73075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livebook-dev",
      "product": "livebook",
      "cwe": "CWE-78",
      "title": "Unescaped deployment environment variables in generated setup commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66297"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-70375",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00981,
      "epss_percentile": 0.59488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashBrownCMS",
      "product": "hashbrown-cms",
      "cwe": "CWE-78",
      "title": "HashBrown CMS - OS Command Injection via Git Deployer Branch Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70375"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-70374",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0097,
      "epss_percentile": 0.59146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashBrownCMS",
      "product": "hashbrown-cms",
      "cwe": "CWE-78",
      "title": "HashBrown CMS - OS Command Injection in Media Upload Thumbnail Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70374"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-17623",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00963,
      "epss_percentile": 0.58878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "title": "Langflow is affected OS Command Injection in Model Context Protocol features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17623"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-48168",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00905,
      "epss_percentile": 0.57054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-862",
      "title": "PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48168"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-71284",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00889,
      "epss_percentile": 0.56544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fledge-iot",
      "product": "fledge",
      "cwe": "CWE-78",
      "title": "Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71284"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-20200",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00843,
      "epss_percentile": 0.55108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Unified Computing System (Standalone)",
      "cwe": "CWE-141",
      "title": "Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20200"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-17505",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00804,
      "epss_percentile": 0.53901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "TranslatePress – Translate Multilingual sites with AI Translation",
      "cwe": "CWE-79",
      "title": "TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17505"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-17625",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0078,
      "epss_percentile": 0.53105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "title": "Langflow is affected by OS Command Injection in Model Context Protocol features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17625"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-15979",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00773,
      "epss_percentile": 0.529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keywordrush",
      "product": "Content Egg – Affiliate Product Importer & Price Comparison",
      "cwe": "CWE-22",
      "title": "Content Egg <= 11.3.0 - Authenticated (Author+) Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15979"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-49004",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00689,
      "epss_percentile": 0.49966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "NX799J (Red Magic 11 Air)",
      "cwe": "CWE-89",
      "title": "PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49004"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-12000",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00662,
      "epss_percentile": 0.48893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberlord92",
      "product": "Page and Post Restriction",
      "cwe": "CWE-862",
      "title": "Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12000"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-6147",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00657,
      "epss_percentile": 0.48674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lightsyncpro",
      "product": "LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock",
      "cwe": "CWE-434",
      "title": "LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6147"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-6627",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00616,
      "epss_percentile": 0.46819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "WPFormify – Stripe Payments with Form and Checkout",
      "cwe": "CWE-862",
      "title": "WPFormify <= 1.1.1 - Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6627"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-18907",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00586,
      "epss_percentile": 0.45453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TECNO Mobile",
      "product": "Hi Browser",
      "cwe": "CWE-23",
      "title": "PathTravelsal Vulnerability in com.talpa.hibrowser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18907"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-66747",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00579,
      "epss_percentile": 0.45102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zbtlink",
      "product": "CPE2801 Firmware",
      "cwe": "CWE-506",
      "title": "ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66747"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-67870",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00576,
      "epss_percentile": 0.44968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67870"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-69111",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00568,
      "epss_percentile": 0.44592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "milvus-io",
      "product": "milvus",
      "cwe": "CWE-306",
      "title": "Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69111"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-18895",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00567,
      "epss_percentile": 0.44541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1250GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18895"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-18897",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00567,
      "epss_percentile": 0.4454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1250GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18897"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-61486",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00566,
      "epss_percentile": 0.44491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Lucy",
      "cwe": "CWE-121",
      "title": "Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61486"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-17532",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00561,
      "epss_percentile": 0.44193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seraphinitesoft",
      "product": "Seraphinite Accelerator",
      "cwe": "CWE-79",
      "title": "Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17532"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-61484",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00554,
      "epss_percentile": 0.43838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Lucy",
      "cwe": "CWE-502",
      "title": "Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61484"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-6020",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin",
      "cwe": "CWE-470",
      "title": "ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6020"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-64577",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00537,
      "epss_percentile": 0.42939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gtp: check skb_pull_data() return in gtp1u_send_echo_resp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64577"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-71207",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00531,
      "epss_percentile": 0.42622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mrswapnilsahu",
      "product": "Stock-Inventory-Management-System",
      "cwe": "CWE-89",
      "title": "Stock-Inventory-Management-System - Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71207"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-67623",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00528,
      "epss_percentile": 0.42476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-829",
      "title": "Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67623"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-61483",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Lucy",
      "cwe": "CWE-674",
      "title": "Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61483"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-61485",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Lucy",
      "cwe": "CWE-789",
      "title": "Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61485"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-17556",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17556"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-48834",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00494,
      "epss_percentile": 0.40385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-400",
      "title": "Apache Answer: Denial of service via crafted Accept-Language header parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48834"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-66274",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton-J",
      "cwe": "CWE-674",
      "title": "Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66274"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-67465",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton Dotnet",
      "cwe": "CWE-770",
      "title": "Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67465"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-67551",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton Dotnet",
      "cwe": "CWE-789",
      "title": "Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67551"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-67589",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid ProtonJ2",
      "cwe": "CWE-789",
      "title": "Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67589"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-67590",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid ProtonJ2",
      "cwe": "CWE-674",
      "title": "Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67590"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-68074",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68074"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-55707",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.40001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Neutron",
      "cwe": "CWE-863",
      "title": "In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55707"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-67552",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.39736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton Dotnet",
      "cwe": "CWE-674",
      "title": "Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67552"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-67588",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.39735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid ProtonJ2",
      "cwe": "CWE-770",
      "title": "Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67588"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-68060",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.39735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68060"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-68073",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.39735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-674",
      "title": "Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68073"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-8400",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00482,
      "epss_percentile": 0.39661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-470",
      "title": "Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8400"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-16022",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.3964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Swiss Federal Office of Information Technology, Systems and Telecommunication",
      "product": "@oblique/cli",
      "cwe": "CWE-78",
      "title": "Command Injection in @oblique/cli",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16022"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-67592",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00478,
      "epss_percentile": 0.39401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid ProtonJ2",
      "cwe": "CWE-770",
      "title": "Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67592"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-9192",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-287",
      "title": "Authentication bypass in Progress MarkLogic Server ODBC App Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9192"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-18898",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18898"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-71190",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Swift",
      "cwe": "CWE-1333",
      "title": "In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The \"qdtext\" pattern (?:[^\"]|\\\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71190"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-67866",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMonitoredItems path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67866"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-67867",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67867"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-67869",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67869"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-67871",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67871"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-5581",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.3797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sh1zen",
      "product": "Multi Uploader for Gravity Forms",
      "cwe": "CWE-862",
      "title": "Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5581"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-18901",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H3C",
      "product": "NX15",
      "cwe": "CWE-749",
      "title": "H3C NX15 Web API esps service.add routine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18901"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-61891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-22",
      "title": "In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61891"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-17632",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17632"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-68746",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.3739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livebook-dev",
      "product": "livebook",
      "cwe": "CWE-636",
      "title": "Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68746"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-71320",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-74",
      "title": "Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71320"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2025-63823",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-798",
      "title": "My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63823"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-15996",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00436,
      "epss_percentile": 0.36508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-674",
      "title": "Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15996"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-67531",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agentfront",
      "product": "frontmcp",
      "cwe": "CWE-94",
      "title": "FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67531"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-59675",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-770",
      "title": "Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59675"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-14553",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "zportals",
      "cwe": "CWE-434",
      "title": "Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14553"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-66257",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66257"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-66273",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton-J",
      "cwe": "CWE-789",
      "title": "Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66273"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-9190",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-444",
      "title": "HTTP request smuggling in Progress MarkLogic Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9190"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-17613",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.3544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Penpot",
      "product": "Penpot",
      "cwe": "CWE-862",
      "title": "CVE-2026-17613",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17613"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-67864",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.3542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67864"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-67865",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67865"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-67872",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67872"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-71321",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-407",
      "title": "Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71321"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-17630",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-184",
      "title": "Langflow is affected by security vulnerabilities in Model Context Protocol features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17630"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-66275",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Proton-J: Incoming session flow control window can be exceeded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66275"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-66276",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton-J",
      "cwe": "CWE-606",
      "title": "Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66276"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-66277",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.3536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66277"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-67591",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid ProtonJ2",
      "cwe": "CWE-770",
      "title": "Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67591"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-68075",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Broker-J: Incoming session flow control window can be exceeded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68075"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-68077",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.3536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-606",
      "title": "Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68077"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-68080",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.3536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-406",
      "title": "Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68080"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-71237",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0042,
      "epss_percentile": 0.35253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Miantang",
      "product": "IoT-PHP",
      "cwe": "CWE-89",
      "title": "Miantang IoT-PHP - Unauthenticated SQL Injection in /userlogin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71237"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-67553",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton Dotnet",
      "cwe": "CWE-770",
      "title": "Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67553"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-67554",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton Dotnet",
      "cwe": "CWE-606",
      "title": "Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67554"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-67555",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Proton Dotnet",
      "cwe": "CWE-770",
      "title": "Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67555"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-68078",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Qpid Broker-J",
      "cwe": "CWE-770",
      "title": "Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68078"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-67863",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67863"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-12609",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-22",
      "title": "In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path stays within the plugin's directory. An unauthenticated network attacker can send percent-encoded `../` sequences (`%2e%2e%2f`) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12609"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-71248",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Harsh21Patel",
      "product": "Inventory-Management-System-PHP",
      "cwe": "CWE-89",
      "title": "Inventory-Management-System-PHP - Unauthenticated SQL Injection in Login and Product Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71248"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-67873",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.33519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67873"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-71314",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.004,
      "epss_percentile": 0.33411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-400",
      "title": "Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71314"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-16940",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Custom Fields",
      "cwe": "CWE-22",
      "title": "Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16940"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-17633",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17633"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-11454",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00395,
      "epss_percentile": 0.32913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trainingbusinesspros",
      "product": "Groundhogg — CRM, Newsletters, and Marketing Automation",
      "cwe": "CWE-639",
      "title": "Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11454"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-60023",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-200",
      "title": "Apache Answer: Unauthorized disclosure of deleted or pending answer content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60023"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-6079",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ho3einie",
      "product": "Material Dashboard",
      "cwe": "CWE-862",
      "title": "Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6079"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-20310",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00391,
      "epss_percentile": 0.32437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Controller",
      "cwe": "CWE-59",
      "title": "Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20310"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-9195",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-22",
      "title": "Cross-site scripting in Progress MarkLogic Server Query Console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9195"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-15918",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikAppointments Services Booking Calendar",
      "cwe": "CWE-89",
      "title": "VikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15918"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-8182",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8182"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-70610",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-1321",
      "title": "Electron: contextBridge object copy honors prototype setters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70610"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2025-70962",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70962"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-71269",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "node-red",
      "product": "node-red",
      "cwe": "CWE-22",
      "title": "Node-RED Library API Path Traversal Leading to Arbitrary File Read/Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71269"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-14587",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neo4j",
      "product": "Enterprise Edition",
      "cwe": "CWE-130",
      "title": "Unathenticated connection can hold Bolt channel open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14587"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-18531",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Maximo Application Suite",
      "cwe": "CWE-330",
      "title": "IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18531"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-5651",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "2wstechnologies",
      "product": "Askeet — Talk to Your WooCommerce Data",
      "cwe": "CWE-89",
      "title": "Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5651"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-66881",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livebook-dev",
      "product": "livebook",
      "cwe": "CWE-23",
      "title": "Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66881"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-17624",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17624"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-18881",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.3086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "realmag777",
      "product": "TableOn – WordPress Posts Table Filterable",
      "cwe": "CWE-89",
      "title": "TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18881"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-70431",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Multijob Plugin",
      "cwe": "CWE-94",
      "title": "Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70431"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-8183",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8183"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-48911",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-306",
      "title": "Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48911"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-71310",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00373,
      "epss_percentile": 0.30552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-400",
      "title": "rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71310"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-71215",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "art-template",
      "product": "art-template",
      "cwe": "CWE-22",
      "title": "art-template - Path Traversal in Sub-Template Resolution via include()/extend()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71215"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-18959",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00372,
      "epss_percentile": 0.30486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yushine",
      "product": "InnoShop",
      "cwe": "CWE-22",
      "title": "yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18959"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-8478",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.3039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8478"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-46581",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Mojarra",
      "cwe": "CWE-22",
      "title": "In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46581"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-8761",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00369,
      "epss_percentile": 0.30089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokaninc",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy",
      "cwe": "CWE-862",
      "title": "Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8761"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-71289",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.29901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA-AMMOS",
      "product": "anms",
      "cwe": "CWE-306",
      "title": "NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71289"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-6639",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wupsales",
      "product": "AI Copilot – Content Generator",
      "cwe": "CWE-862",
      "title": "AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenticated Sensitive Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6639"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-71268",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00365,
      "epss_percentile": 0.29749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thiagoralves",
      "product": "OpenPLC_v3",
      "cwe": "CWE-22",
      "title": "OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71268"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-20272",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.2962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-74",
      "title": "Cisco IOS XE Software Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20272"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-15372",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP 2FA",
      "cwe": "CWE-287",
      "title": "WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15372"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-71279",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koenkk",
      "product": "zigbee2mqtt",
      "cwe": "CWE-22",
      "title": "Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71279"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-70612",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-284",
      "title": "Electron: Sandboxed iframes can launch external protocol handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70612"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-71231",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thebradleysanders",
      "product": "IOTSmartHome",
      "cwe": "CWE-89",
      "title": "IOTSmartHome - Unauthenticated SQL Injection via lastLogin Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71231"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-71278",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iot-ecology",
      "product": "rust-iot-platform",
      "cwe": "CWE-94",
      "title": "rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71278"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-70377",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theotherphil",
      "product": "imagecli",
      "cwe": "CWE-789",
      "title": "imagecli - Uncontrolled Memory Allocation via Unbounded scale Ratio Causes Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70377"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-18903",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00357,
      "epss_percentile": 0.2898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yeqifu",
      "product": "warehouse",
      "cwe": "CWE-22",
      "title": "yeqifu warehouse FileController.java path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18903"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-7753",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylemix",
      "product": "Cost Calculator Builder",
      "cwe": "CWE-862",
      "title": "Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7753"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-64566",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64566"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-7529",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.2831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wisemattic",
      "product": "wiseCampaign – WooCommerce Conversions Made Easy",
      "cwe": "CWE-862",
      "title": "wiseCampaign <= 1.1.16 - Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7529"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-71262",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IoTSharp",
      "product": "IoTSharp",
      "cwe": "CWE-306",
      "title": "IoTSharp BlobStorageController Missing Authentication and Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71262"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-60053",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00349,
      "epss_percentile": 0.28048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-613",
      "title": "Apache Answer: Residual Administrative API Key Access After Role or Account Revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60053"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-15572",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-843",
      "title": "Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15572"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-10025",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.2795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "QRadar",
      "cwe": "CWE-611",
      "title": "IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10025"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-20288",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.27769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Unified Computing System (Standalone)",
      "cwe": "CWE-146",
      "title": "Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20288"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-20124",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-772",
      "title": "Cisco IOS XE Software SNMP Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20124"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-55523",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-918",
      "title": "PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55523"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-54416",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pluck-cms",
      "product": "Pluck CMS",
      "cwe": "CWE-434",
      "title": "Pluck CMS - Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54416"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-17617",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.26622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Application Gateway Operator",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in IBM Application Gateway Operator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17617"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-15281",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gm_alex",
      "product": "User Access Manager",
      "cwe": "CWE-89",
      "title": "User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15281"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-18411",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acrisure",
      "product": "KARR BT",
      "cwe": "CWE-321",
      "title": "Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18411"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-7658",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7658"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-70607",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-20",
      "title": "Electron: window.open features string controls some window options considered privileged",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70607"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-4431",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00334,
      "epss_percentile": 0.26468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeruby",
      "product": "Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress",
      "cwe": "CWE-862",
      "title": "Easy Post Submission <= 2.3.0 - Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4431"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-11421",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce",
      "cwe": "CWE-89",
      "title": "ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17.4 - Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11421"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-20263",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-388",
      "title": "Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20263"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-20301",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-606",
      "title": "Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20301"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-71319",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "devtools",
      "cwe": "CWE-94",
      "title": "Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71319"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-15360",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ajax Load More",
      "cwe": "CWE-89",
      "title": "Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15360"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-71213",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00323,
      "epss_percentile": 0.25193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typemill",
      "product": "typemill",
      "cwe": "CWE-307",
      "title": "typemill - No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71213"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-60009",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-22",
      "title": "In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests. Because `multipart/form-data` is a CORS-safelisted request type, a cross-origin web page can trigger the write with no preflight and no credentials, resulting in an unauthenticated arbitrary file write outside the workspace to any absolute path the backend process can write. This can escalate to remote code execution, for example by overwriting a startup-executed file such as `~/.bashrc`. Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60009"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-70609",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.2512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-94",
      "title": "Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70609"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-20308",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-269",
      "title": "Cisco IOS XE Software Web-Based Management Interface Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20308"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-71292",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "intelliants",
      "product": "subrion",
      "cwe": "CWE-89",
      "title": "Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71292"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-7329",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00317,
      "epss_percentile": 0.24578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-269",
      "title": "Privilege escalation in Progress MarkLogic Server REST query interfaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7329"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-64578",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: validate compound request size before reading StructureSize2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64578"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-16602",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Passster",
      "cwe": "CWE-200",
      "title": "Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16602"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-16603",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Passster",
      "cwe": "CWE-200",
      "title": "Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16603"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-16604",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Passster",
      "cwe": "CWE-200",
      "title": "Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16604"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-16605",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MultiVendorX",
      "cwe": "CWE-862",
      "title": "MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16605"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-18322",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsysticcom",
      "product": "Smart Popup by Supsystic",
      "cwe": "CWE-269",
      "title": "Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18322"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-71309",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.2419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-22",
      "title": "rclone: Incomplete path validation allows backend root escape in serve restic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71309"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-34966",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-918",
      "title": "Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34966"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-71238",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DjangoCRM",
      "product": "django-crm",
      "cwe": "CWE-798",
      "title": "DjangoCRM - Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71238"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-71270",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stirling-Tools",
      "product": "Stirling-PDF",
      "cwe": "CWE-918",
      "title": "Stirling-PDF Server-Side Request Forgery via /api/v1/convert/url/pdf WeasyPrint Subprocess",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71270"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-10716",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Directus",
      "product": "Directus",
      "cwe": "CWE-89",
      "title": "Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10716"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-20303",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00309,
      "epss_percentile": 0.23615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Controller",
      "cwe": "CWE-20",
      "title": "Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20303"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-9077",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-807",
      "title": "Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9077"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-71254",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "debevv",
      "product": "nanoMODBUS",
      "cwe": "CWE-787",
      "title": "nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71254"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-71256",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "debevv",
      "product": "nanoMODBUS",
      "cwe": "CWE-125",
      "title": "nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71256"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-71267",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rxi",
      "product": "microtar",
      "cwe": "CWE-121",
      "title": "microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71267"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-16100",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.6",
      "cwe": "CWE-770",
      "title": "Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16100"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-71287",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-89",
      "title": "Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Blind SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71287"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-71288",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koha Community",
      "product": "Koha",
      "cwe": "CWE-89",
      "title": "Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.pl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71288"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-71291",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bolt",
      "product": "core",
      "cwe": "CWE-1336",
      "title": "Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71291"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-48912",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-639",
      "title": "Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48912"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-50749",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-863",
      "title": "Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50749"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-16055",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.2311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Contest Gallery",
      "cwe": "CWE-287",
      "title": "Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16055"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-44945",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-441",
      "title": "Cross-Cluster Impersonation Confused-Deputy Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44945"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-7646",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is affected by security vulnerabilities in Model Context Protocol features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7646"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-11969",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "WP TripAdvisor Review Slider",
      "cwe": "CWE-89",
      "title": "WP TripAdvisor Review Slider <= 14.3 - Authenticated (Administrator+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11969"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-16036",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "miniOrange 2FA",
      "cwe": "CWE-287",
      "title": "miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16036"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-71232",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magicblack",
      "product": "maccms10",
      "cwe": "CWE-94",
      "title": "MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71232"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-71316",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-524",
      "title": "Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71316"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-5116",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sevenspark",
      "product": "DTX – Dynamic Text Extension for Contact Form 7",
      "cwe": "CWE-79",
      "title": "Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5116"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-15210",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00296,
      "epss_percentile": 0.22236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "OTP Login With Phone Number, OTP Verification",
      "cwe": "CWE-287",
      "title": "Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15210"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-16561",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Sunshine Photo Cart",
      "cwe": "CWE-862",
      "title": "Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16561"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-16736",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-284",
      "title": "User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16736"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-70426",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-502",
      "title": "In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70426"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-9196",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.2184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9196"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-15573",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-178",
      "title": "Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15573"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-11920",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beardev",
      "product": "JoomSport – for Sports: Team & League, Football, Hockey & more",
      "cwe": "CWE-89",
      "title": "JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11920"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-71235",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "absmach",
      "product": "magistrala",
      "cwe": "CWE-94",
      "title": "Magistrala IoT Platform - Unrestricted Go/Lua Script Execution in Rules Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71235"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-71243",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adaltas",
      "product": "backmeup",
      "cwe": "CWE-78",
      "title": "backmeup (npm) - OS Command Injection via Backup Option Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71243"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-17626",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-266",
      "title": "Langflow is affected by security vulnerabilities in Model Context Protocol features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17626"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-71283",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fledge-iot",
      "product": "fledge",
      "cwe": "CWE-22",
      "title": "Fledge IoT Gateway Backup Restore Tar Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71283"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-71252",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.2099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raghav993",
      "product": "toner-management",
      "cwe": "CWE-862",
      "title": "toner-management - Unauthenticated State-Changing Admin Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71252"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-8446",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-306",
      "title": "Langflow is affected by security vulnerabilities in Model Context Protocol features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8446"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-71241",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lyric777",
      "product": "Book-Management-System",
      "cwe": "CWE-306",
      "title": "Book-Management-System - Unauthenticated Disclosure of Student PII and Borrowing History",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71241"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-14574",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-1321",
      "title": "In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by `PreferenceServiceImpl.doResolve` for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (`.theia/settings.json` or `.vscode/settings.json`) can pollute `Object.prototype` when the user opens the workspace, potentially altering application logic across the Theia process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14574"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-71263",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00278,
      "epss_percentile": 0.20392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cwalter-at",
      "product": "FreeModbus",
      "cwe": "CWE-787",
      "title": "FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71263"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-70378",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theotherphil",
      "product": "imagecli",
      "cwe": "CWE-1284",
      "title": "imagecli - Negative carve Ratio Bypasses Bounds Check and Crashes Process via Reachable Panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70378"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-18933",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-downloadmanager",
      "product": "wp-downloadmanager",
      "cwe": "CWE-434",
      "title": "wp-downloadmanager - Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18933"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-18969",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rongzhitong",
      "product": "Visual Integrated Command and Dispatch Platform",
      "cwe": "CWE-284",
      "title": "Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18969"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-9273",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "Membership Plugin – Kadence Memberships",
      "cwe": "CWE-640",
      "title": "Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9273"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-71312",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-78",
      "title": "rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71312"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-10059",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00272,
      "epss_percentile": 0.1966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-266",
      "title": "Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10059"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-71281",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "peft",
      "cwe": "CWE-502",
      "title": "peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA and CorDA Modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71281"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-7520",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mailmunch",
      "product": "Mailmunch Forms for Mailchimp",
      "cwe": "CWE-862",
      "title": "MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7520"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-20304",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00269,
      "epss_percentile": 0.19168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Controller",
      "cwe": "CWE-284",
      "title": "Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20304"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-52466",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-863",
      "title": "Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\\Controller\\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52466"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-71214",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA-AMMOS",
      "product": "plandev (sequencing-server)",
      "cwe": "CWE-306",
      "title": "NASA-AMMOS plandev - Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71214"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-20268",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-119",
      "title": "Cisco IOS XE Software Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20268"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-20269",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-664",
      "title": "Cisco IOS XE Software Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20269"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-20270",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-682",
      "title": "Cisco IOS XE Software Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20270"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-20271",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-691",
      "title": "Cisco IOS XE Software Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20271"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-20273",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.1893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-20",
      "title": "Cisco IOS XE Software Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20273"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-71315",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-178",
      "title": "Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71315"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-16573",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bit Form",
      "cwe": "CWE-79",
      "title": "Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16573"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-7726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "techeshta",
      "product": "Layouts for WPBakery",
      "cwe": "CWE-862",
      "title": "Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7726"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-7557",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00266,
      "epss_percentile": 0.18669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-347",
      "title": "SAML authentication bypass in Progress MarkLogic Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7557"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-5062",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supercleanse",
      "product": "PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links",
      "cwe": "CWE-89",
      "title": "PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5062"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-55739",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crater-invoice",
      "product": "Crater",
      "cwe": "CWE-639",
      "title": "Crater - Missing Tenant-Ownership Check in CustomerPolicy Allows Cross-Company Customer Data Theft and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55739"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-20313",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Controller",
      "cwe": "CWE-1284",
      "title": "Cisco Catalyst SD-WAN Security Hardening Release - Memory Corruption Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20313"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-71202",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kosinix",
      "product": "raster",
      "cwe": "CWE-191",
      "title": "raster - Integer Underflow in crop() Offset Handling Causes Capacity-Overflow Panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71202"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-18968",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ttttonyhe",
      "product": "OBlog",
      "cwe": "CWE-79",
      "title": "ttttonyhe OBlog tags.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18968"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-54876",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.1804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-401",
      "title": "Client-Side Memory Leak in OCSP Response Checking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54876"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-39923",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flarum",
      "product": "Flarum Framework",
      "cwe": "CWE-324",
      "title": "Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39923"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-13477",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "QRadar",
      "cwe": "CWE-78",
      "title": "IBM QRadar SIEM is vulnerable to remote code execution by privileged users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13477"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-70608",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-693",
      "title": "Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70608"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-55747",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The-Pocket",
      "product": "PocketFlow (pocketflow-coding-agent cookbook example)",
      "cwe": "CWE-22",
      "title": "PocketFlow - Path Traversal in pocketflow-coding-agent Cookbook Example File Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55747"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-8709",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-269",
      "title": "Privilege escalation in Progress MarkLogic Server REST document patch operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8709"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-9193",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-269",
      "title": "Privilege escalation in Progress MarkLogic Server Hadoop integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9193"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-18854",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shandong Hoteam",
      "product": "PDM Product Data Management System",
      "cwe": "CWE-74",
      "title": "Shandong Hoteam PDM Product Data Management System DataService GetStoredClassByFilter sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18854"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-18859",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ESAFENET",
      "product": "CDG",
      "cwe": "CWE-74",
      "title": "ESAFENET CDG usbkey;logindojojs sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18859"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-18958",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imranrisal-dev",
      "product": "Student-Management-System",
      "cwe": "CWE-74",
      "title": "imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18958"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-18970",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rongzhitong",
      "product": "Visual Integrated Command and Dispatch Platform",
      "cwe": "CWE-74",
      "title": "Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18970"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-16102",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-284",
      "title": "Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16102"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-71313",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-22",
      "title": "rclone: Local Encoding Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71313"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-71192",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Swift",
      "cwe": "CWE-863",
      "title": "In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71192"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-71191",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Swift",
      "cwe": "CWE-863",
      "title": "In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71191"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-20028",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Terminal Services Agent",
      "cwe": "CWE-266",
      "title": "Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20028"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-11977",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "afthemes",
      "product": "WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars",
      "cwe": "CWE-89",
      "title": "WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11977"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-15941",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Relevanssi",
      "product": "Relevanssi Premium – A Better Search",
      "cwe": "CWE-89",
      "title": "Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15941"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-15230",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YayPricing",
      "cwe": "CWE-284",
      "title": "YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15230"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-54418",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "Leantime",
      "cwe": "CWE-862",
      "title": "Leantime - Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54418"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-70427",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.1647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-59",
      "title": "Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70427"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-10090",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00247,
      "epss_percentile": 0.16305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-267",
      "title": "Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10090"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-7456",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webocoders",
      "product": "Udimi Tools",
      "cwe": "CWE-862",
      "title": "Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7456"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-20267",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.15988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-284",
      "title": "Cisco IOS XE Software Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20267"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-71234",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "documize",
      "product": "community",
      "cwe": "CWE-863",
      "title": "Documize Community - Attachment Download Authorization Bypass via Non-Validated secure Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71234"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-5108",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "superpwa",
      "product": "Super Progressive Web Apps",
      "cwe": "CWE-79",
      "title": "Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5108"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-70428",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-22",
      "title": "Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70428"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-0931",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M-Files Corporation",
      "product": "M-Files Server",
      "cwe": "CWE-1286",
      "title": "Denial-of-service vulnerability in M-Files Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0931"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-71277",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iot-ecology",
      "product": "rust-iot-platform",
      "cwe": "CWE-287",
      "title": "rust-iot-platform Authentication Bypass via Non-Validated Authorization Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71277"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-70429",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-178",
      "title": "Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70429"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-71225",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stephan Muelle",
      "product": "libkcapi",
      "cwe": "CWE-330",
      "title": "Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71225"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-12762",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.1545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak For Business Automation",
      "cwe": "CWE-538",
      "title": "Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12762"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-71271",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usememos",
      "product": "memos",
      "cwe": "CWE-918",
      "title": "Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71271"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-15452",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Smash Balloon Social Photo Feed – Easy Social Feeds Plugin",
      "cwe": "CWE-79",
      "title": "Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15452"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-71311",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-93",
      "title": "rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71311"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-16143",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikRentItems Flexible Rental Management System",
      "cwe": "CWE-79",
      "title": "VikRentItems Flexible Rental Management System <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16143"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-9201",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-326",
      "title": "Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9201"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-71260",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.1437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esphome",
      "product": "esphome",
      "cwe": "CWE-522",
      "title": "ESPHome web_server Plaintext Password Disclosure via JSON \"value\" Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71260"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-9205",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00231,
      "epss_percentile": 0.14263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-338",
      "title": "Langflow is affected by weaknesses in secret handling and sensitive configuration access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9205"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-70617",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spacebar Server",
      "product": "Spacebar Server",
      "cwe": "CWE-862",
      "title": "Spacebar Server Missing Authorization via Group DM Recipient Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70617"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-53992",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ProjectSend",
      "product": "ProjectSend",
      "cwe": "CWE-79",
      "title": "Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53992"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-17506",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bensibley",
      "product": "Independent Analytics – WordPress Analytics Plugin",
      "cwe": "CWE-79",
      "title": "Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17506"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-71282",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chirpstack",
      "product": "chirpstack",
      "cwe": "CWE-89",
      "title": "ChirpStack SQLite Backend SQL Injection via Device Tag Key in ListDevices Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71282"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-18856",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Poesis",
      "product": "Rhymix CMS",
      "cwe": "CWE-918",
      "title": "Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18856"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-10547",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-284",
      "title": "Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10547"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-71239",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DjangoCRM",
      "product": "django-crm",
      "cwe": "CWE-1336",
      "title": "DjangoCRM - Server-Side Template Injection in Mass Mail Message Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71239"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-39924",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flarum",
      "product": "Flarum Framework",
      "cwe": "CWE-613",
      "title": "Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39924"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-71294",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-502",
      "title": "Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71294"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-25703",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "NeuVector",
      "cwe": "CWE-202",
      "title": "Potential information leakage from manager /network/graph API in NeuVector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25703"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-10128",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-200",
      "title": "Langflow is affected by weaknesses in secret handling and sensitive configuration access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10128"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-7327",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-269",
      "title": "Privilege escalation in Progress MarkLogic Server REST API document processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7327"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2025-63822",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63822"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-70436",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins External Workspace Manager Plugin",
      "cwe": "CWE-862",
      "title": "Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70436"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-71255",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.1277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "debevv",
      "product": "nanoMODBUS",
      "cwe": "CWE-787",
      "title": "nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71255"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-8790",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antoineh",
      "product": "Football Pool",
      "cwe": "CWE-79",
      "title": "Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8790"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-16968",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.1264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GeoDirectory",
      "cwe": "CWE-200",
      "title": "GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16968"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-16746",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MultiVendorX",
      "cwe": "CWE-639",
      "title": "MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16746"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-71250",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "firefly-iii",
      "product": "firefly-iii",
      "cwe": "CWE-918",
      "title": "Firefly III - Webhook URL Validation Explicitly Allows Loopback and Is Bypassable via DNS Rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71250"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-7869",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7869"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-70615",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boringproxy",
      "product": "boringproxy",
      "cwe": "CWE-93",
      "title": "boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70615"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-71206",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-shiori",
      "product": "shiori",
      "cwe": "CWE-613",
      "title": "shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71206"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-71242",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crater-invoice",
      "product": "crater",
      "cwe": "CWE-639",
      "title": "Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71242"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-71285",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "louislam",
      "product": "uptime-kuma",
      "cwe": "CWE-79",
      "title": "Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71285"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-71293",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-200",
      "title": "Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71293"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-9203",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-918",
      "title": "Server-side request forgery in Progress MarkLogic Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9203"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-71208",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubesphere",
      "product": "KubeSphere",
      "cwe": "CWE-918",
      "title": "KubeSphere - SSRF via Unvalidated Cluster CRD Connection Endpoint in Cluster Reconciliation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71208"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-71318",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.1141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-20",
      "title": "Nuxt: Unauthorized Component Instantiation via Server Island Props",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71318"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-70432",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Multijob Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70432"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-20198",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.1106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Enterprise NFV Infrastructure Software",
      "cwe": "CWE-79",
      "title": "Cisco Integrated Management Controller Cross-Site Scripting Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20198"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-70604",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-942",
      "title": "Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70604"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-0516",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "SonicOS",
      "cwe": "CWE-644",
      "title": "A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0516"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-55998",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-204",
      "title": "Cluster Existence Oracle via Unauthenticated Import Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55998"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-7105",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xpro",
      "product": "Xpro Addons — 140+ Widgets for Elementor",
      "cwe": "CWE-862",
      "title": "Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7105"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-16442",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00202,
      "epss_percentile": 0.10476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-346",
      "title": "Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16442"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-7657",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow OSS is affected by server-side request forgery in provider validation and API request functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7657"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-71244",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paperless-ngx",
      "product": "paperless-ngx",
      "cwe": "CWE-918",
      "title": "Paperless-ngx - Mail Account Test Connection Leaks Stored IMAP/OAuth Credentials to Attacker-Controlled Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71244"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-71251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "akaunting",
      "product": "akaunting",
      "cwe": "CWE-639",
      "title": "Akaunting - Cross-Company Media IDOR in Customer Portal Download Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71251"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-6972",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sonalsinha21",
      "product": "SKT Skill Bar",
      "cwe": "CWE-79",
      "title": "SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6972"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-7441",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alphawolf",
      "product": "Simple Yearly Archive",
      "cwe": "CWE-79",
      "title": "Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7441"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-18927",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imranrisal-dev",
      "product": "Student-Management-System",
      "cwe": "CWE-284",
      "title": "imranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18927"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-71233",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.1008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "invoiceninja",
      "product": "invoiceninja",
      "cwe": "CWE-79",
      "title": "InvoiceNinja - Stored XSS via Invoice/Quote Terms Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71233"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-71236",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grocy",
      "product": "grocy",
      "cwe": "CWE-79",
      "title": "Grocy - Stored XSS via HTMLPurifier Output Double-Decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71236"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-20312",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.10011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Controller",
      "cwe": "CWE-312",
      "title": "Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20312"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-70616",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.10008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boringproxy",
      "product": "boringproxy",
      "cwe": "CWE-833",
      "title": "boringproxy 0.10.0 Resource Exhaustion DoS via GET /loading endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70616"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-70605",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-918",
      "title": "Electron: HTTP redirect followed into local file loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70605"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-71204",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-284",
      "title": "changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71204"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-71264",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aircoookie",
      "product": "WLED",
      "cwe": "CWE-862",
      "title": "WLED Unauthenticated Configuration Disclosure via /json/cfg and Global Settings-PIN Lock State",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71264"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-55524",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-367",
      "title": "PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55524"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-70448",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Ivy Report Plugin",
      "cwe": "CWE-611",
      "title": "Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70448"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-71265",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "domoticz",
      "product": "domoticz",
      "cwe": "CWE-121",
      "title": "Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71265"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-16981",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "DHL Shipping Germany for WooCommerce",
      "cwe": "CWE-639",
      "title": "DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16981"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-70618",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spacebar Server",
      "product": "Spacebar Server",
      "cwe": "CWE-862",
      "title": "Spacebar Server Missing Authorization via member-ids Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70618"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-20289",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-532",
      "title": "Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20289"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-18896",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lavkush-maurya",
      "product": "Student-Registration-System",
      "cwe": "CWE-74",
      "title": "lavkush-maurya Student-Registration-System changepass.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18896"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-71276",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "absmach",
      "product": "magistrala",
      "cwe": "CWE-89",
      "title": "Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71276"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-71240",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.0889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DjangoCRM",
      "product": "django-crm",
      "cwe": "CWE-601",
      "title": "DjangoCRM - Unauthenticated Open Redirect via toggle_default_sorting next_url Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71240"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-70601",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-693",
      "title": "Electron: Context isolation bypass via Function.prototype.bind hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70601"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-71203",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-306",
      "title": "changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71203"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-15656",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Maximo Application Suite",
      "cwe": "CWE-614",
      "title": "IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15656"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-64572",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00186,
      "epss_percentile": 0.08554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: fib: free fib_alias with kfree_rcu() on insert error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64572"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-16583",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More",
      "cwe": "CWE-79",
      "title": "Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16583"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-16071",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-269",
      "title": "Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16071"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-21766",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Digital Experience and Digital Experience Compose",
      "cwe": "CWE-522",
      "title": "HCL Digital Experience and Digital Experience Compose insufficiently protects credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21766"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-70596",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "Ghost: Cross-Site Scripting in Feature Image Captions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70596"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-70430",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-284",
      "title": "Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70430"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-70444",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Violation Comments to GitLab Plugin",
      "cwe": "CWE-693",
      "title": "A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70444"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-71280",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-shiori",
      "product": "shiori",
      "cwe": "CWE-918",
      "title": "go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71280"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-70595",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-918",
      "title": "Ghost: Server-Side Request Forgery Mitigation Issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70595"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-9130",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9130"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-71247",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "documenso",
      "product": "documenso",
      "cwe": "CWE-863",
      "title": "Documenso - Assistant Recipient Can Forge Another Signer's Signature in Sequential-Signing Documents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71247"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-71274",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openshwprojects",
      "product": "OpenBK7231T_App",
      "cwe": "CWE-79",
      "title": "OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71274"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-70437",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00173,
      "epss_percentile": 0.07076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Webhook Secret Credentials Provider Plugin",
      "cwe": "CWE-208",
      "title": "Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70437"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2025-15677",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00173,
      "epss_percentile": 0.07088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GeoDirectory",
      "cwe": "CWE-79",
      "title": "GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15677"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-14304",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Accessibility Tools Framework (ACTF)",
      "cwe": "CWE-611",
      "title": "In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14304"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-9081",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow OSS is affected by server-side request forgery in provider validation and API request functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9081"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-71211",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow",
      "cwe": "CWE-918",
      "title": "mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71211"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-16993",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.06867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "DHL Shipping Germany for WooCommerce",
      "cwe": "CWE-200",
      "title": "DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16993"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-70433",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins HCL AppScan Plugin",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70433"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-70438",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Parameterized Remote Trigger Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70438"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-70442",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Google Chat Notification Plugin",
      "cwe": "CWE-285",
      "title": "Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70442"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-70445",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Sauce OnDemand Plugin",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70445"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-70446",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins CodeSonar Plugin",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70446"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-7444",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cornelraiu-1",
      "product": "Search Analytics for WP",
      "cwe": "CWE-352",
      "title": "Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7444"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-71201",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-863",
      "title": "In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71201"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-66298",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livebook-dev",
      "product": "livebook",
      "cwe": "CWE-346",
      "title": "JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66298"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-12730",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Business Automation Workflow containers and traditional",
      "cwe": "CWE-297",
      "title": "Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12730"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-71272",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usememos",
      "product": "memos",
      "cwe": "CWE-367",
      "title": "Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71272"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-63457",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "HPE Integrated Lights-Out 6 (iLO 6)",
      "cwe": "CWE-400",
      "title": "A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63457"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-70443",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Horreum Plugin",
      "cwe": "CWE-269",
      "title": "Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70443"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-70447",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins AWS CodeBuild Plugin",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70447"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-71246",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixelfed",
      "product": "pixelfed",
      "cwe": "CWE-918",
      "title": "Pixelfed - Authenticated SSRF via Remote URL Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71246"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-15587",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00161,
      "epss_percentile": 0.0582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Google SecOps (Chronicle SOAR)",
      "cwe": "CWE-346",
      "title": "Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15587"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-70602",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-284",
      "title": "Electron: Extension tab APIs operate across session boundaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70602"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-70439",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.0584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins XML Job to Job DSL Plugin",
      "cwe": "CWE-862",
      "title": "Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70439"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-66885",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livebook-dev",
      "product": "livebook",
      "cwe": "CWE-352",
      "title": "Livebook Teams identity callback lacks state binding, allowing login CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66885"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-71205",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-307",
      "title": "changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71205"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-20311",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-126",
      "title": "Cisco IOS XE Software Web UI Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20311"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-70606",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-668",
      "title": "Electron: ProtocolResponse.url reuses the default session cache instead of the registering session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70606"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-71210",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mealie-recipes",
      "product": "mealie",
      "cwe": "CWE-367",
      "title": "mealie - DNS-Rebinding TOCTOU in SSRF Guard Allows Internal Network and Cloud Metadata Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71210"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-64569",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64569"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-64571",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: p54: validate RX frame length in p54_rx_eeprom_readback()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64571"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-64573",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.0533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: qca: fix NVM tag length underflow in TLV parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64573"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-64579",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64579"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-71286",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miguelcobain",
      "product": "ember-dynamic-render-template",
      "cwe": "CWE-1336",
      "title": "ember-dynamic-render-template Client-Side Template Injection via Unsanitized templateString",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71286"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-16443",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00154,
      "epss_percentile": 0.05115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-347",
      "title": "Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16443"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-55522",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55522"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-64570",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: fix fils_discovery double free on alloc failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64570"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-55996",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.0475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-770",
      "title": "Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55996"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-17578",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong",
      "product": "Kong Event Gateway",
      "cwe": "CWE-323",
      "title": "Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17578"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-71249",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "299ko",
      "product": "299Ko",
      "cwe": "CWE-79",
      "title": "299Ko - Unauthenticated Reflected XSS in Public Contact Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71249"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-18953",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-transform-mcp-server",
      "cwe": "CWE-22",
      "title": "Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18953"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-70599",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-346",
      "title": "Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70599"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-70440",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Qualys Container Scanning Connector Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70440"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-70441",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Summary Display Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70441"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-7326",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "MarkLogic Server",
      "cwe": "CWE-352",
      "title": "Cross-site request forgery in Progress MarkLogic Server Admin UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7326"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-17583",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thermo Fisher",
      "product": "Applied Biosystems 3500/3500xL Series Data Collection Software",
      "cwe": "CWE-353",
      "title": "Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17583"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-70600",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-1021",
      "title": "Electron: Cross-origin iframe can position native autofill popup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70600"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-66839",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Integrated Systems Technologies, Inc.",
      "product": "NetKids iMark",
      "cwe": "CWE-428",
      "title": "NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66839"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-44605",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-190",
      "title": "Rpm: heap buffer overflow in ndb slot table parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-70611",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-78",
      "title": "Electron: DevTools embedder handler executes arbitrary files via shell open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70611"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-20294",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Manager",
      "cwe": "CWE-319",
      "title": "Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20294"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-8029",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00134,
      "epss_percentile": 0.03349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "SmartLife",
      "cwe": "CWE-89",
      "title": "SQL Injection Vulnerability in ZTE SmartLife App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8029"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-16942",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Custom HTML Page",
      "cwe": "CWE-79",
      "title": "WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16942"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-71275",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openshwprojects",
      "product": "OpenBK7231T_App",
      "cwe": "CWE-79",
      "title": "OpenBK7231T - Reflected XSS via OTA host Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71275"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-70376",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0013,
      "epss_percentile": 0.0311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pluck-cms",
      "product": "Pluck CMS",
      "cwe": "CWE-352",
      "title": "Pluck CMS - CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70376"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-49331",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-345",
      "title": "Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49331"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-16613",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GDPR Cookie Compliance",
      "cwe": "CWE-352",
      "title": "GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16613"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-12410",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "CCleaner",
      "cwe": "CWE-59",
      "title": "CCleaner local privilege escalation via link following on uninstall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12410"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-71261",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mackron",
      "product": "dr_libs",
      "cwe": "CWE-190",
      "title": "dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buffer Overflow on 32-bit Builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71261"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-71266",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syoyo",
      "product": "tinyobjloader-c",
      "cwe": "CWE-121",
      "title": "tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71266"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-19027",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-125",
      "title": "HDF5 out-of-bounds heap read in N-Bit filter decompression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19027"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-19026",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-476",
      "title": "Nbit filter NULL/short parameter-array dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19026"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-19028",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-125",
      "title": "HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19028"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-19024",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-476",
      "title": "HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19024"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-70435",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins SCM-Manager Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70435"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-64567",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: reject free space cache with more entries than pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64567"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-64568",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64568"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-64580",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64580"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-71259",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esphome",
      "product": "esphome",
      "cwe": "CWE-184",
      "title": "ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71259"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-64575",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: tcp: fix double sock release on batch realloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64575"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-64582",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Fix a use-after-free problem in rxe_mmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64582"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-19023",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-822",
      "title": "HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19023"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-19025",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-369",
      "title": "HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19025"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-71273",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openshwprojects",
      "product": "OpenBK7231T_App",
      "cwe": "CWE-352",
      "title": "OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable and WiFi Hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71273"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-64574",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: tear down new links on vif update error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64574"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-71226",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stephan Muelle",
      "product": "libkcapi",
      "cwe": "CWE-416",
      "title": "Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71226"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-64576",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nexthop: initialize extack in nh_res_bucket_migrate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64576"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-66344",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Integrated Systems Technologies, Inc.",
      "product": "NetKids iMark",
      "cwe": "CWE-427",
      "title": "NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66344"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-18485",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "NI-PAL",
      "cwe": "CWE-1285",
      "title": "Local Privilege Escalation in NI-PAL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18485"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-64581",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: fix sk_dst_cache double-free in xfrm_user_policy()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64581"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-71227",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stephan Muelle",
      "product": "libkcapi",
      "cwe": "CWE-835",
      "title": "Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71227"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-17515",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings",
      "cwe": "CWE-200",
      "title": "MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17515"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-8470",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00111,
      "epss_percentile": 0.01494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-327",
      "title": "Langflow is affected by weaknesses in secret handling and sensitive configuration access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8470"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-71212",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "indravoyager",
      "product": "xidown",
      "cwe": "CWE-88",
      "title": "xidown - Argument Injection via Unterminated yt-dlp Command Line Construction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71212"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-18954",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "documentdb-mcp-server",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18954"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-70603",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-20",
      "title": "Electron: shell.openPath path validation bypass via embedded null byte",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70603"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-70598",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.001,
      "epss_percentile": 0.00994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-125",
      "title": "Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70598"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-70434",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins SCM-Manager Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70434"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-18839",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00084,
      "epss_percentile": 0.00314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rpm-software-management",
      "product": "popt",
      "cwe": "CWE-191",
      "title": "Popt-devel: popt-static: size_t underflow in singleoptionhelp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18839"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-70597",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.00242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-367",
      "title": "Electron: Parent process code-sign check is spoofable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70597"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-55997",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rancher",
      "product": "rancher",
      "cwe": "CWE-312",
      "title": "Long-lived Rancher registration token exposed in plaintext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55997"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-0669",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-0669 (Fortra Goanywhere MFT). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-35078",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-35078 (Ivanti Endpoint Manager Mobile). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-3519",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-3519 (Citrix NetScaler ADC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-38831",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-38831. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-51378",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-51378. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-55956",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-55956. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-26633",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-26633 (Microsoft Windows 10 Version 1507). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-66024",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-66024 (xwiki-contrib application-blog-ui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18766",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18766 (chetans9 core-php-admin-panel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18774 (NousResearch hermes-agent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18784",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18784 (o6 open62541). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18788",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18788 (Trippo ResponsiveFilemanager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18811",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18811 (H3C NX15). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18812 (H3C NX15). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18813",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18813 (H3C NX15). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18814",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18814 (H3C NX15). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18819",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18819 (RackTables). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3609",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3609 (Wellbia XIGNCODE3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4629",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4629 (Red Hat build of Keycloak 26.4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46581 (Eclipse Foundation Eclipse Mojarra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54904",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54904 (ruby-concurrency concurrent-ruby). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55554",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55554 (dompdf). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61515",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61515 (Puwell Technology Inc. IP Camera). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66297 (livebook-dev livebook). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66881 (livebook-dev livebook). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67196",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67196 (perspective-dev perspective). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67200",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67200 (perspective-dev perspective). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69098",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69098 (Cinnamon kotaemon). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70619",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70619 (odysseus-dev odysseus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70620 (odysseus-dev odysseus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-60137",
      "detail": "DUE DATE PASSED — CVE-2026-60137 (WordPress). CISA remediation deadline was August 4, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-35078",
      "detail": "RESCORED — CVE-2023-35078 (Ivanti Endpoint Manager Mobile). CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-41265",
      "detail": "RESCORED — CVE-2023-41265. CVSS 9.6 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-41266",
      "detail": "RESCORED — CVE-2023-41266. CVSS 8.2 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-11667",
      "detail": "RESCORED — CVE-2024-11667 (Zyxel ATP series firmware). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-51378",
      "detail": "RESCORED — CVE-2024-51378. CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-55591",
      "detail": "RESCORED — CVE-2024-55591 (Fortinet FortiOS). CVSS 9.6 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16158",
      "detail": "RESCORED — CVE-2026-16158 (@fastify/reply-from). CVSS 8.7 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18852",
      "detail": "RESCORED — CVE-2026-18852 (epsilla-cloud vectordb). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18853",
      "detail": "RESCORED — CVE-2026-18853 (ZomboDroid Meme Generator App). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-24457",
      "detail": "RESCORED — CVE-2026-24457 (Eclipse Foundation Eclipse OpenMQ). CVSS 9.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-3609",
      "detail": "RESCORED — CVE-2026-3609 (Wellbia XIGNCODE3). CVSS 5.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-9793",
      "detail": "RESCORED — CVE-2026-9793 (Red Hat build of Keycloak 26.4). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-3483",
      "detail": "ENRICHED — CVE-2021-3483 (Linux kernel). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-3501",
      "detail": "ENRICHED — CVE-2021-3501 (Linux kernel). Received CVSS 7.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-1353",
      "detail": "ENRICHED — CVE-2022-1353 (Linux kernel). Received CVSS 7.1 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
