{
  "day": "2026-08-06",
  "boundary": "UTC calendar day",
  "published_count": 482,
  "by_severity": {
    "CRITICAL": 87,
    "HIGH": 187,
    "MEDIUM": 145,
    "LOW": 51
  },
  "kev_count": 1,
  "exploit_reference_count": 5,
  "awaiting_enrichment_count": 12,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-65400",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00751,
      "epss_percentile": 0.52159,
      "kev": true,
      "kev_due_at": "2026-08-21",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-287",
      "title": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65400"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-15733",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.13545,
      "epss_percentile": 0.96147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WGDashboard",
      "product": "WGDashboard",
      "cwe": "CWE-78",
      "title": "WGDashboard Remote Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15733"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-19034",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02469,
      "epss_percentile": 0.8321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19034"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-19035",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02469,
      "epss_percentile": 0.8321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato qoslimit new_qoslimit_start os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19035"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-19036",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02469,
      "epss_percentile": 0.8321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato wanoptions sub_40F88C os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19036"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-53976",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01899,
      "epss_percentile": 0.78005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bohdan Triapitsyn",
      "product": "OpenChamber",
      "cwe": "CWE-22",
      "title": "OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53976"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-19041",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0166,
      "epss_percentile": 0.74765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MissionSquad",
      "product": "mcp-api",
      "cwe": "CWE-74",
      "title": "MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19041"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-67261",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01603,
      "epss_percentile": 0.73876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Virtual Storage Integrator for VMware vSphere Client",
      "cwe": "CWE-78",
      "title": "Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67261"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-18980",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01329,
      "epss_percentile": 0.68755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nearai",
      "product": "ironclaw",
      "cwe": "CWE-74",
      "title": "nearai ironclaw shell.rs classify_command_risk command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18980"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-19022",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01293,
      "epss_percentile": 0.67989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenHands",
      "cwe": "CWE-74",
      "title": "OpenHands send_pull_request.py initialize_repo command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19022"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-53975",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01084,
      "epss_percentile": 0.62582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bohdan Triapitsyn",
      "product": "OpenChamber",
      "cwe": "CWE-78",
      "title": "OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53975"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-50515",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0091,
      "epss_percentile": 0.57201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Service Bus",
      "cwe": "CWE-502",
      "title": "Azure Service Bus Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50515"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-66733",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00887,
      "epss_percentile": 0.56497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eukaryot",
      "product": "sonic3air",
      "cwe": "CWE-789",
      "title": "Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66733"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-64677",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00755,
      "epss_percentile": 0.52293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ankitects",
      "product": "anki",
      "cwe": "CWE-22",
      "title": "Anki's local HTTP server is vulnerable to directory traversal attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64677"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-64654",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00736,
      "epss_percentile": 0.51665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cli",
      "product": "cli",
      "cwe": "CWE-150",
      "title": "GitHub CLI: Terminal escape sequence injection in multiple `gh` commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64654"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-71502",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00706,
      "epss_percentile": 0.50576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "cti-transmute",
      "cwe": "CWE-79",
      "title": "Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-Transmute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71502"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-67434",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00701,
      "epss_percentile": 0.50411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPCSStandards",
      "product": "PHP_CodeSniffer",
      "cwe": "CWE-78",
      "title": "PHP_CodeSniffer gitblame report command injection via crafted filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67434"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-19044",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00696,
      "epss_percentile": 0.50204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LeeSinLiang",
      "product": "godot-mcp",
      "cwe": "CWE-74",
      "title": "LeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19044"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-66909",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00693,
      "epss_percentile": 0.50085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-502",
      "title": "Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66909"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2024-39024",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.49948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-39024"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-67689",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00685,
      "epss_percentile": 0.4979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67689"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-19047",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00683,
      "epss_percentile": 0.49709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NocteDefensor",
      "product": "LudusMCP",
      "cwe": "CWE-74",
      "title": "NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19047"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-15734",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00676,
      "epss_percentile": 0.49454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WGDashboard",
      "product": "WGDashboard",
      "cwe": "CWE-1336",
      "title": "WGDashboard Server-Side Template Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15734"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-59115",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00635,
      "epss_percentile": 0.47698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra Provisioning Service",
      "cwe": "CWE-35",
      "title": "Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59115"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-49163",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00622,
      "epss_percentile": 0.47125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Application Insights Profiler",
      "cwe": "CWE-22",
      "title": "Application Insights Profiler Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49163"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-19045",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NocteDefensor",
      "product": "LudusMCP",
      "cwe": "CWE-74",
      "title": "NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.showSecretDialog command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19045"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-43629",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00619,
      "epss_percentile": 0.4697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-787",
      "title": "llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43629"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-15991",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00606,
      "epss_percentile": 0.46371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitpressadmin",
      "product": "File Manager",
      "cwe": "CWE-862",
      "title": "File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15991"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-18649",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.46129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18649"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-70558",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00596,
      "epss_percentile": 0.45892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataLinkDC",
      "product": "Dinky",
      "cwe": "CWE-434",
      "title": "Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70558"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-67688",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00587,
      "epss_percentile": 0.45493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67688"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-71476",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.45248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nrwl",
      "product": "nx",
      "cwe": "CWE-22",
      "title": "Nx: Zip-Slip in the self-hosted remote cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71476"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-67422",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.45243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facelessuser",
      "product": "pymdown-extensions",
      "cwe": "CWE-1333",
      "title": "pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67422"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-14812",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00569,
      "epss_percentile": 0.44637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Premium SEO",
      "cwe": "CWE-912",
      "title": "Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14812"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-50159",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00569,
      "epss_percentile": 0.44632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-94",
      "title": "Mermaid allows CSS injection applying to sibling elements of the diagram",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50159"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-48085",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00553,
      "epss_percentile": 0.43816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-862",
      "title": "OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48085"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-71324",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00551,
      "epss_percentile": 0.43724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-444",
      "title": "Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71324"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-19150",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00545,
      "epss_percentile": 0.43375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19150"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-19151",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00545,
      "epss_percentile": 0.43374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19151"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-19168",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00545,
      "epss_percentile": 0.43375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19168"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-5857",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.42952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contiki-NG",
      "product": "Contiki-NG",
      "cwe": "CWE-787",
      "title": "Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5857"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-5855",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00537,
      "epss_percentile": 0.42961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contiki-NG",
      "product": "Contiki-NG",
      "cwe": "CWE-125",
      "title": "Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5855"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-34501",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00528,
      "epss_percentile": 0.42482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Portable Runtime Utility",
      "cwe": "CWE-122",
      "title": "Apache Portable Runtime Utility: Heap buffer overflow in APR redis client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34501"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-34502",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00528,
      "epss_percentile": 0.42481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Portable Runtime Utility",
      "cwe": "CWE-122",
      "title": "Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34502"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-67687",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67687"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-3418",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-434",
      "title": "Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3418"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-53977",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00521,
      "epss_percentile": 0.42048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bohdan Triapitsyn",
      "product": "OpenChamber",
      "cwe": "CWE-306",
      "title": "OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53977"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-15459",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "WPMU DEV Dashboard",
      "cwe": "CWE-287",
      "title": "WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15459"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-70633",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timescale",
      "product": "timescaledb",
      "cwe": "CWE-191",
      "title": "TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Iterator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70633"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-64653",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.41039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cli",
      "product": "cli",
      "cwe": "CWE-22",
      "title": "GitHub CLI: Unescaped variable components in request URLs could allow path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64653"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-19149",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.005,
      "epss_percentile": 0.40775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19149"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-68823",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.005,
      "epss_percentile": 0.40777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Confidential Ledger",
      "cwe": "CWE-749",
      "title": "Azure Confidential Ledger Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68823"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-66829",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.005,
      "epss_percentile": 0.40765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rrrene",
      "product": "html_sanitize_ex",
      "cwe": "CWE-601",
      "title": "html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66829"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-18991",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00493,
      "epss_percentile": 0.40323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "NanoClaw",
      "cwe": "CWE-22",
      "title": "nanocoai NanoClaw send_file core.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18991"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-19176",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00492,
      "epss_percentile": 0.40292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19176"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-11976",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.3995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MonsterInsights Pro",
      "cwe": "CWE-912",
      "title": "MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11976"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-56162",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00484,
      "epss_percentile": 0.39754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-287",
      "title": "Azure SQL Database Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56162"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-66709",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebAppick",
      "product": "CTX Feed",
      "cwe": "CWE-94",
      "title": "WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66709"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-70332",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00481,
      "epss_percentile": 0.3963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Online",
      "cwe": "CWE-79",
      "title": "Microsoft Office SharePoint Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70332"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-65553",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wbolt.com",
      "product": "Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件",
      "cwe": "CWE-94",
      "title": "WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65553"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-32327",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00477,
      "epss_percentile": 0.39327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Portable Runtime Utility",
      "cwe": "CWE-674",
      "title": "Apache Portable Runtime Utility: apr-util XML stack recursion crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32327"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-19038",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00475,
      "epss_percentile": 0.39232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MonomythDevelopment",
      "product": "la-forge-mcp",
      "cwe": "CWE-22",
      "title": "MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19038"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-54225",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-770",
      "title": "Apache CXF: Denial of Service attack via large attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54225"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-57819",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-400",
      "title": "Apache CXF: No default restriction on the amount of form parameters per message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57819"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-18427",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/static",
      "product": "@fastify/static",
      "cwe": "CWE-22",
      "title": "@fastify/static vulnerable to route guard bypass via non-canonical path segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18427"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-48087",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-287",
      "title": "OpenReception: WebAuthn passkey injection allows account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48087"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-50481",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.37986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Active Directory",
      "cwe": "CWE-471",
      "title": "Azure Active Directory Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50481"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-48054",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.3792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenZeppelin",
      "product": "contracts-wizard",
      "cwe": "CWE-94",
      "title": "OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48054"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-19137",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19137"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-43630",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00453,
      "epss_percentile": 0.37806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-125",
      "title": "llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43630"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-19177",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19177"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-57817",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00443,
      "epss_percentile": 0.37032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-20",
      "title": "Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57817"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-63508",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Planetary Computer Pro (GeoCatalog)",
      "cwe": "CWE-306",
      "title": "Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63508"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-65667",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams",
      "cwe": "CWE-862",
      "title": "Microsoft Teams Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65667"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-68749",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rrrene",
      "product": "html_sanitize_ex",
      "cwe": "CWE-1333",
      "title": "Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68749"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-68750",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rrrene",
      "product": "html_sanitize_ex",
      "cwe": "CWE-407",
      "title": "Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68750"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-61466",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0044,
      "epss_percentile": 0.36823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-304",
      "title": "Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61466"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-65548",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Muffingroup",
      "product": "Betheme",
      "cwe": "CWE-94",
      "title": "WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65548"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-16268",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletters",
      "cwe": "CWE-918",
      "title": "Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16268"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-19145",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19145"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-19162",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19162"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-19174",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19174"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-47765",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.3608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-862",
      "title": "Frappe: Lack of Permissions in restore/bulk_restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47765"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-65552",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00426,
      "epss_percentile": 0.35727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qstudio",
      "product": "Export User Data",
      "cwe": "CWE-502",
      "title": "WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65552"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-68481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-672",
      "title": "Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68481"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-54489",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.35581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Virtual Storage Integrator for VMware vSphere Client",
      "cwe": "CWE-200",
      "title": "Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54489"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-19166",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00423,
      "epss_percentile": 0.35532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19166"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-19141",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19141"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-19142",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19142"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-19158",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19158"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-19159",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19159"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-62830",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SRE Agent",
      "cwe": "CWE-862",
      "title": "Azure SRE Agent Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62830"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-65668",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Purview eDiscovery",
      "cwe": "CWE-284",
      "title": "Microsoft Purview eDiscovery Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65668"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-19011",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00416,
      "epss_percentile": 0.34845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TinyAGI",
      "cwe": "CWE-73",
      "title": "TinyAGI agents.ts buildSystemPrompt file inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19011"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-70634",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timescale",
      "product": "timescaledb",
      "cwe": "CWE-129",
      "title": "TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70634"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-43631",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00412,
      "epss_percentile": 0.34529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-416",
      "title": "llama.cpp b7492–b9060 Use-After-Free RCE via llama-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43631"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-68079",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-294",
      "title": "Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68079"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-65432",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-611",
      "title": "Apache CXF: XXE via WSDL/XSD import parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65432"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-19040",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00409,
      "epss_percentile": 0.34263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MissionSquad",
      "product": "mcp-api",
      "cwe": "CWE-918",
      "title": "MissionSquad mcp-api dcrClients.ts server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19040"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-64958",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-400",
      "title": "Apache CXF: Denial of service via message header attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64958"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-61632",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facelessuser",
      "product": "pymdown-extensions",
      "cwe": "CWE-22",
      "title": "PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61632"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-19157",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19157"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-19170",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19170"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-65543",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vimeodev",
      "product": "Vimeo",
      "cwe": "CWE-201",
      "title": "WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65543"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-18990",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "letta-ai",
      "product": "LettaBot",
      "cwe": "CWE-287",
      "title": "letta-ai LettaBot API Status Route server.ts missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18990"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-45415",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.33002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-862",
      "title": "Decidim: CSV census record endpoints improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45415"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-5336",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00395,
      "epss_percentile": 0.32847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "DataPress (Dataverse Integration)",
      "cwe": "CWE-200",
      "title": "Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5336"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2025-49506",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Portable Runtime Utility",
      "cwe": "CWE-208",
      "title": "Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-49506"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-47185",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00393,
      "epss_percentile": 0.32662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-79",
      "title": "Frappe Has Broken Access Control in its Workspace Save API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47185"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-48075",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-862",
      "title": "OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48075"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-71439",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-606",
      "title": "Mermaid radar diagrams are vulnerable to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71439"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-59118",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0039,
      "epss_percentile": 0.32327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Copilot Cowork",
      "cwe": "CWE-285",
      "title": "Copilot Cowork Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59118"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-19009",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TinyAGI",
      "cwe": "CWE-73",
      "title": "TinyAGI Message API Endpoint response.ts collectFiles file inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19009"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-28139",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdreams",
      "product": "Ajax Search Lite",
      "cwe": "CWE-502",
      "title": "WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28139"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2025-14561",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.3189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-284",
      "title": "Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14561"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-48079",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-613",
      "title": "OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48079"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-15732",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WGDashboard",
      "product": "WGDashboard",
      "cwe": "CWE-918",
      "title": "WGDashboard Server-Side Request Forgery Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15732"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-56161",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Logic Apps",
      "cwe": "CWE-284",
      "title": "Azure Logic Apps Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56161"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-62896",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams",
      "cwe": "CWE-287",
      "title": "Microsoft Teams Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62896"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-53984",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Efstratios Goudelis",
      "product": "Ground Station",
      "cwe": "CWE-306",
      "title": "Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Data Injection via Socket.IO database_backup full_restore Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53984"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-53985",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Efstratios Goudelis",
      "product": "Ground Station",
      "cwe": "CWE-306",
      "title": "Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53985"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-48071",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-307",
      "title": "OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-tenant lockout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48071"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-17032",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "google-maps-easy-pro",
      "cwe": "CWE-912",
      "title": "Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17032"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-70636",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-862",
      "title": "Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70636"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-19164",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19164"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-19171",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19171"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-19175",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19175"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2025-15039",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server",
      "cwe": "CWE-693",
      "title": "Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15039"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-19144",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19144"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-19169",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19169"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-19138",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19138"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-19010",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TinyAGI",
      "cwe": "CWE-862",
      "title": "TinyAGI Message API Endpoint index.ts processMessage authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19010"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-19111",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "strands-agents-tools",
      "cwe": "CWE-639",
      "title": "Insecure direct object reference in Strands Agents Tools memory tool namespace isolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19111"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-65549",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegtheme",
      "product": "Jeg Kit for Elementor",
      "cwe": "CWE-502",
      "title": "WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65549"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-48082",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0037,
      "epss_percentile": 0.30221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-770",
      "title": "OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48082"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-19153",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19153"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-64597",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.29599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix double-free in SMB2_close() replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64597"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-71327",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-694",
      "title": "Traefik: Gateway API route identity collision allows cross-namespace backend hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71327"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-19146",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00363,
      "epss_percentile": 0.2957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19146"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-34191",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Portable Runtime Utility",
      "cwe": "CWE-89",
      "title": "Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34191"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-19154",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19154"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-19172",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19172"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-48084",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-307",
      "title": "OpenReception doesn't rate limit passphrase login attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48084"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-62836",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00359,
      "epss_percentile": 0.29131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SQL Managed Instance",
      "cwe": "CWE-923",
      "title": "Azure SQL Managed Instance Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62836"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-70635",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timescale",
      "product": "timescaledb",
      "cwe": "CWE-129",
      "title": "TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70635"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-64640",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Polaris",
      "cwe": "CWE-863",
      "title": "Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64640"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-19064",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Examination & Learning Management System",
      "cwe": "CWE-285",
      "title": "SourceCodester Online Examination & Learning Management System view.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19064"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-19160",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00358,
      "epss_percentile": 0.29078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19160"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-71326",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00356,
      "epss_percentile": 0.28843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-287",
      "title": "Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71326"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-19037",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00352,
      "epss_percentile": 0.28384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "WonderTrader",
      "cwe": "CWE-840",
      "title": "WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19037"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-70646",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vovchic17",
      "product": "aiosend",
      "cwe": "CWE-400",
      "title": "aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70646"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-48083",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.28072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-117",
      "title": "OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48083"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-71488",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-407",
      "title": "league/commonmark: Quadratic-time denial of service when parsing crafted Markdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71488"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-57818",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-367",
      "title": "Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57818"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-62873",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00343,
      "epss_percentile": 0.27395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Admin Center",
      "cwe": "CWE-347",
      "title": "Microsoft 365 Admin Center Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62873"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-49391",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-79",
      "title": "Frappe: Stored XSS in Column Headers via Data Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49391"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-3415",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-776",
      "title": "XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3415"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-19008",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00342,
      "epss_percentile": 0.2737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mf-yang",
      "product": "openclaw-cn",
      "cwe": "CWE-59",
      "title": "mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19008"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-70557",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "diboot",
      "product": "diboot-core",
      "cwe": "CWE-639",
      "title": "diboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses Password Hashes and Salts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70557"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-19140",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19140"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-19147",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19147"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-19148",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19148"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-19152",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19152"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-19155",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19155"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-19163",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19163"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-19173",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19173"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-5423",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neo4j",
      "product": "graphql",
      "cwe": "CWE-302",
      "title": "Subscription Authentication Bypass via Unverified connectionParams.jwt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5423"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-48086",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00334,
      "epss_percentile": 0.26459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-269",
      "title": "OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48086"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-28005",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Kadence WooCommerce Email Designer",
      "cwe": "CWE-862",
      "title": "WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28005"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-65507",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sergey",
      "product": "AIWU",
      "cwe": "CWE-266",
      "title": "WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65507"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-43632",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.25947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-416",
      "title": "llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43632"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-19167",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00329,
      "epss_percentile": 0.25852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19167"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-64655",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00329,
      "epss_percentile": 0.25866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cli",
      "product": "cli",
      "cwe": "CWE-185",
      "title": "GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64655"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-70559",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataLinkDC",
      "product": "Dinky",
      "cwe": "CWE-306",
      "title": "Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70559"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-28146",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-22",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28146"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-71436",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-835",
      "title": "Mermaid XY Charts are vulnerable to an infinite loop DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71436"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-53983",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Efstratios Goudelis",
      "product": "Ground Station",
      "cwe": "CWE-918",
      "title": "Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53983"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-71554",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-hyper",
      "product": "h2",
      "cwe": "CWE-444",
      "title": "h2: Duplicate Host header could facilitate request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71554"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-45414",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-639",
      "title": "Decidim: JWT-backed authentication can be replayed across organizations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45414"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-71445",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail-project",
      "product": "ail-framework",
      "cwe": "CWE-79",
      "title": "Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71445"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-19069",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00319,
      "epss_percentile": 0.24764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System treatmentrecord.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19069"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-19070",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00319,
      "epss_percentile": 0.24764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewadmin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19070"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-19071",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00319,
      "epss_percentile": 0.24764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewappointment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19071"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-18487",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "Epiphany",
      "cwe": "CWE-451",
      "title": "Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18487"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-65559",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tychesoftwares",
      "product": "Order Delivery Date for WooCommerce",
      "cwe": "CWE-266",
      "title": "WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65559"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-65554",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lattepress",
      "product": "AnsPress – Question and answer",
      "cwe": "CWE-862",
      "title": "WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65554"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-65556",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MihChe",
      "product": "WPBruiser {no- Captcha anti-Spam}",
      "cwe": "CWE-502",
      "title": "WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65556"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-65571",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "69 Clothing",
      "cwe": "CWE-502",
      "title": "WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65571"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-65572",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "A.Williams",
      "cwe": "CWE-502",
      "title": "WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65572"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-65573",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Abelle",
      "cwe": "CWE-502",
      "title": "WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65573"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-65574",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AncoraThemes",
      "product": "Abogado",
      "cwe": "CWE-502",
      "title": "WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65574"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-65575",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AncoraThemes",
      "product": "Accalia",
      "cwe": "CWE-502",
      "title": "WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65575"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-65576",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AncoraThemes",
      "product": "Adrena",
      "cwe": "CWE-502",
      "title": "WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65576"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-65577",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AncoraThemes",
      "product": "Advice",
      "cwe": "CWE-502",
      "title": "WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65577"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-65578",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AncoraThemes",
      "product": "Agora",
      "cwe": "CWE-502",
      "title": "WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65578"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-65579",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axiomthemes",
      "product": "Agricola",
      "cwe": "CWE-502",
      "title": "WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65579"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-65581",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "AI ANN",
      "cwe": "CWE-502",
      "title": "WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65581"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-19062",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chiuwingyan",
      "product": "house",
      "cwe": "CWE-74",
      "title": "chiuwingyan house selectall.action sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19062"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-64665",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-287",
      "title": "Statamic: Account takeover via OAuth email matching without email-verification check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64665"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-18974",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heshengtao",
      "product": "super-agent-party",
      "cwe": "CWE-200",
      "title": "heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18974"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-18258",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scripta",
      "product": "eScriptorium",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in eScriptorium",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18258"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-14831",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Booking",
      "cwe": "CWE-602",
      "title": "Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14831"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-45573",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-918",
      "title": "Decidim: Push subscriptions can be abused for server-side requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45573"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-66470",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shabti Kaplan",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-862",
      "title": "WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66470"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-48077",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-862",
      "title": "OpenReception: GET appointment by ID returns full appointment record without authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48077"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-16636",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmanageninja",
      "product": "FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP",
      "cwe": "CWE-79",
      "title": "FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16636"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-64662",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-639",
      "title": "Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64662"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-19019",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00305,
      "epss_percentile": 0.23193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "poco-ai",
      "product": "poco-agent",
      "cwe": "CWE-459",
      "title": "poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19019"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-66710",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "E2Pdf",
      "product": "e2pdf",
      "cwe": "CWE-98",
      "title": "WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66710"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-45378",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-200",
      "title": "Decidim: Verification documents can be downloaded through reusable links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45378"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-18973",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heshengtao",
      "product": "super-agent-party",
      "cwe": "CWE-918",
      "title": "heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18973"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-1728",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00297,
      "epss_percentile": 0.22289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-269",
      "title": "Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1728"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-64663",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-470",
      "title": "Statamic: Unsafe method invocation via Antlers template resolution allows data destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64663"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-19161",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00296,
      "epss_percentile": 0.22221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19161"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-66425",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder",
      "cwe": "CWE-288",
      "title": "WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66425"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-48088",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00293,
      "epss_percentile": 0.21942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-862",
      "title": "OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48088"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-62918",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams",
      "cwe": "CWE-347",
      "title": "Microsoft Teams Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62918"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-65508",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-89",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65508"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-65520",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "WP OAuth Server",
      "cwe": "CWE-89",
      "title": "WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65520"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-19000",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-918",
      "title": "JeecgBoot Anonymous Chat Attachment send server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19000"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-14842",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Made Easy",
      "cwe": "CWE-639",
      "title": "Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14842"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-66665",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brandexponents",
      "product": "Type Hub",
      "cwe": "CWE-434",
      "title": "WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66665"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-71437",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.2156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-1321",
      "title": "Mermaid Architecture diagrams are vulnerable to prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71437"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-66843",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0029,
      "epss_percentile": 0.21568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rrrene",
      "product": "html_sanitize_ex",
      "cwe": "CWE-829",
      "title": "html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66843"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-17264",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Medixant",
      "product": "RadiAnt DICOM",
      "cwe": "CWE-787",
      "title": "Medixant RadiAnt DICOM Out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17264"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-65504",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivanbebek",
      "product": "BOX NOW Delivery Croatia",
      "cwe": "CWE-862",
      "title": "WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65504"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-65523",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "approveme",
      "product": "Formidable Forms Signature Online Contract Automation",
      "cwe": "CWE-639",
      "title": "WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0.1 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65523"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-28111",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.2117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Forminator",
      "cwe": "CWE-266",
      "title": "WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28111"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-19127",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitroomHQ",
      "product": "postiz-app",
      "cwe": "CWE-345",
      "title": "Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19127"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-13399",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payment Plugins for PayPal WooCommerce",
      "cwe": "CWE-639",
      "title": "Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13399"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-64598",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: Fix error code in smb2_aead_req_alloc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64598"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-18995",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netease-youdao",
      "product": "LobsterAI",
      "cwe": "CWE-200",
      "title": "netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18995"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-48074",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0028,
      "epss_percentile": 0.20538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-863",
      "title": "OpenReception: Staff deletion removes pending invites cross-tenant by email match",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48074"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-18325",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-79",
      "title": "Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18325"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-65547",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Constant Contact",
      "product": "Creative Mail",
      "cwe": "CWE-89",
      "title": "WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65547"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-65569",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpjobportal",
      "product": "WP Job Portal",
      "cwe": "CWE-89",
      "title": "WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65569"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-48080",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-200",
      "title": "OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deployment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48080"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-16731",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.1999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OMICRON electronics GmbH",
      "product": "OMICRON StationScout",
      "cwe": "CWE-208",
      "title": "Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16731"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-16054",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Drag and Drop Multiple File Upload for WooCommerce",
      "cwe": "CWE-73",
      "title": "Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16054"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-67621",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-862",
      "title": "Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67621"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-19066",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Examination & Learning Management System",
      "cwe": "CWE-285",
      "title": "SourceCodester Online Examination & Learning Management System view_students.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19066"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-19165",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.1979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19165"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-66695",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "W3 Total Cache",
      "cwe": "CWE-35",
      "title": "WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66695"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-10524",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CoCart",
      "cwe": "CWE-472",
      "title": "CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10524"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-66662",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shabti Kaplan",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-266",
      "title": "WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66662"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-19156",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19156"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-5134",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loca Software Informatics Technology Ltd. Co.",
      "product": "CMS",
      "cwe": "CWE-89",
      "title": "SQLi in Loca Software's CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5134"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-63687",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-345",
      "title": "Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63687"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-18276",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scripta",
      "product": "eScriptorium",
      "cwe": "CWE-862",
      "title": "Missing Authorization in eScriptorium",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18276"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-19021",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Computer Repair Shop Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19021"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-12713",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPCargo Track & Trace",
      "cwe": "CWE-89",
      "title": "WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12713"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-65583",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.1819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-345",
      "title": "Apache CXF: Self-issued ID token claims validation skipped",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65583"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-65542",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rajat Varlani",
      "product": "Super Socializer",
      "cwe": "CWE-288",
      "title": "WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65542"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-16620",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPC Name Your Price for WooCommerce",
      "cwe": "CWE-472",
      "title": "WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16620"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-16315",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OMICRON electronics GmbH",
      "product": "OMICRON StationGuard",
      "cwe": "CWE-208",
      "title": "Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16315"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-63725",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxsmin",
      "product": "sysPass",
      "cwe": "CWE-78",
      "title": "sysPass FileBackupService Authenticated OS Command Injection via Backup Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63725"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-13153",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Gutenberg Essential Blocks",
      "cwe": "CWE-200",
      "title": "Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13153"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-13154",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Gutenberg Essential Blocks",
      "cwe": "CWE-200",
      "title": "Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13154"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-18050",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.1742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Manager",
      "cwe": "CWE-200",
      "title": "Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18050"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2024-6541",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Micro Integrator",
      "cwe": "CWE-20",
      "title": "Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-6541"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-19065",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Examination & Learning Management System",
      "cwe": "CWE-284",
      "title": "SourceCodester Online Examination & Learning Management System upload_files.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19065"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-68747",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00254,
      "epss_percentile": 0.17163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rrrene",
      "product": "html_sanitize_ex",
      "cwe": "CWE-74",
      "title": "CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68747"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-19110",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00254,
      "epss_percentile": 0.17123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DataGear",
      "cwe": "CWE-79",
      "title": "DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19110"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-5856",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contiki-NG",
      "product": "Contiki-NG",
      "cwe": "CWE-125",
      "title": "Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5856"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-13342",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Security Optimizer",
      "cwe": "CWE-693",
      "title": "Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13342"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-11983",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spacetime",
      "product": "Ad Inserter – Ad Manager & AdSense Ads",
      "cwe": "CWE-862",
      "title": "Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11983"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-64664",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-200",
      "title": "Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64664"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-18400",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metaslider",
      "product": "Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider",
      "cwe": "CWE-79",
      "title": "Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18400"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-48078",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-200",
      "title": "OpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48078"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-19067",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System treatment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19067"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-19068",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System treatmentdetail.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19068"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-62857",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fedify-dev",
      "product": "fedify",
      "cwe": "CWE-918",
      "title": "Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62857"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-16954",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Engine",
      "cwe": "CWE-200",
      "title": "AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16954"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-67622",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-639",
      "title": "Flowise 3.1.4 IDOR in OpenAI Assistants Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67622"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-71446",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail-project",
      "product": "ail-framework",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in AIL Framework Domain Screenshot View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71446"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-28140",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "JetFormBuilder",
      "cwe": "CWE-862",
      "title": "WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28140"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-18996",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00245,
      "epss_percentile": 0.15968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-266",
      "title": "cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18996"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-18510",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "TranslatePress – Translate Multilingual sites with AI Translation",
      "cwe": "CWE-79",
      "title": "TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18510"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-48076",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-863",
      "title": "OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48076"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-66452",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IT-Recht Kanzlei",
      "product": "Legal Text Connector of the IT-Recht Kanzlei",
      "cwe": "CWE-862",
      "title": "WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66452"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-3430",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Creative Mail",
      "cwe": "CWE-89",
      "title": "Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3430"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-63637",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgraph-io",
      "product": "dgraph",
      "cwe": "CWE-943",
      "title": "Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63637"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2024-6832",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Enterprise Integrator",
      "cwe": "CWE-693",
      "title": "Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-6832"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-54717",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silverstripe",
      "product": "silverstripe-cms",
      "cwe": "CWE-79",
      "title": "Silverstripe: XSS in breadcrumbs in page list view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54717"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-28169",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITHEMES",
      "product": "YITH WooCommerce Zoom Magnifier",
      "cwe": "CWE-497",
      "title": "WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28169"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-66683",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Zone",
      "product": "Custom CSS and JavaScript",
      "cwe": "CWE-201",
      "title": "WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66683"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-66684",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akshay Menariya",
      "product": "Export Import Menus",
      "cwe": "CWE-201",
      "title": "WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66684"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-71434",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-434",
      "title": "Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71434"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2025-12317",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Enterprise Integrator",
      "cwe": "CWE-613",
      "title": "Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12317"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-64586",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmfmac: drain bus_reset work on device removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64586"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-32469",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPKube",
      "product": "CAPTCHA 4WP",
      "cwe": "CWE-290",
      "title": "WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32469"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-65502",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Element Pack Elementor Addons",
      "cwe": "CWE-290",
      "title": "WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65502"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-18277",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scripta",
      "product": "eScriptorium",
      "cwe": "CWE-862",
      "title": "Missing Authorization in eScriptorium",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18277"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-12605",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse GlassFish",
      "cwe": "CWE-918",
      "title": "In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12605"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-65546",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QODE",
      "product": "Qode Tours",
      "cwe": "CWE-89",
      "title": "WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65546"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-66447",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nickboss",
      "product": "WordPress File Upload",
      "cwe": "CWE-89",
      "title": "WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66447"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-15149",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.1486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Hotel Booking",
      "cwe": "CWE-20",
      "title": "WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15149"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-16067",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.1486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Booking Manager for WooCommerce (Pro)",
      "cwe": "CWE-472",
      "title": "Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16067"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-16619",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "miniOrange 2FA",
      "cwe": "CWE-307",
      "title": "miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16619"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-14314",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PeproDev WooCommerce Receipt Uploader",
      "cwe": "CWE-200",
      "title": "PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14314"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-65570",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.1454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hamid Alinia",
      "product": "Login with phone number",
      "cwe": "CWE-290",
      "title": "WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65570"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-71447",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail-project",
      "product": "ail-framework",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in Chat and Forum Translation Controls in ail-framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71447"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-65551",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.1435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soflyy",
      "product": "Breakdance",
      "cwe": "CWE-862",
      "title": "WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65551"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-66451",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event SOlution",
      "cwe": "CWE-288",
      "title": "WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66451"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-16065",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Welcart e-Commerce",
      "cwe": "CWE-89",
      "title": "Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16065"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-14225",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.14064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-20",
      "title": "Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14225"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-28180",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mercado Pago",
      "product": "Mercado Pago payments for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28180"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-32548",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SureCart",
      "product": "SureCart",
      "cwe": "CWE-862",
      "title": "WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32548"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-66370",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rrrene",
      "product": "html_sanitize_ex",
      "cwe": "CWE-601",
      "title": "html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66370"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-70637",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hfiref0x",
      "product": "LightFTP",
      "cwe": "CWE-820",
      "title": "LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70637"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-18275",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scripta",
      "product": "eScriptorium",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in eScriptorium",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18275"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-68480",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00227,
      "epss_percentile": 0.13655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/bugs: Make Safe-RET robust against interrupt injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68480"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-71433",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langgraph",
      "cwe": "CWE-200",
      "title": "LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71433"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-5430",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00223,
      "epss_percentile": 0.13181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Universal Gateway",
      "cwe": "CWE-347",
      "title": "Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5430"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-66708",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "Total Upkeep",
      "cwe": "CWE-862",
      "title": "WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66708"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-18359",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scripta",
      "product": "eScriptorium",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in eScriptorium",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18359"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-65541",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "solutioned",
      "product": "Staff Training",
      "cwe": "CWE-862",
      "title": "WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65541"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2025-15674",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Passster",
      "cwe": "CWE-863",
      "title": "Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15674"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-66712",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.1238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Simple Membership",
      "cwe": "CWE-862",
      "title": "WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66712"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-18993",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-266",
      "title": "NousResearch hermes-agent Memory Toolset model_tools.py access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18993"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-66692",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Colissimo",
      "product": "Colissimo Officiel : Méthodes de livraison pour WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66692"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-61959",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-79",
      "title": "WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61959"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-0673",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons",
      "cwe": "CWE-93",
      "title": "Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0673"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-16290",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfileGrid",
      "cwe": "CWE-862",
      "title": "ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16290"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-70632",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-787",
      "title": "FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70632"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-18976",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-266",
      "title": "NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18976"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-18992",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "CowAgent",
      "cwe": "CWE-285",
      "title": "zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18992"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-18997",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.1144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-285",
      "title": "cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18997"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-18998",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.1144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-266",
      "title": "cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18998"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-19005",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.1144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "NanoClaw",
      "cwe": "CWE-266",
      "title": "nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19005"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-19006",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mf-yang",
      "product": "openclaw-cn",
      "cwe": "CWE-285",
      "title": "mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19006"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-19007",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mf-yang",
      "product": "openclaw-cn",
      "cwe": "CWE-266",
      "title": "mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19007"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-14240",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "tourmaster",
      "cwe": "CWE-200",
      "title": "Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14240"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2025-13909",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server",
      "cwe": "CWE-20",
      "title": "Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13909"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-66711",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amir Helzer",
      "product": "WooCommerce Multilingual & Multicurrency",
      "cwe": "CWE-79",
      "title": "WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66711"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-19059",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FoundationAgents",
      "product": "MetaGPT",
      "cwe": "CWE-22",
      "title": "FoundationAgents MetaGPT editor.py read path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19059"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-43628",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-191",
      "title": "llama.cpp b3978–b9058 Integer Underflow via DRY Sampler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43628"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-16734",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Stripe Payment Forms by WP Full Pay",
      "cwe": "CWE-862",
      "title": "Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16734"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-47194",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-346",
      "title": "Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47194"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-71478",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-79",
      "title": "league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71478"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2025-6508",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-79",
      "title": "User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-6508"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-19020",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System servicetype.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19020"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-66685",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alex",
      "product": "Featured Video Plus",
      "cwe": "CWE-201",
      "title": "WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66685"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-14306",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": "CWE-639",
      "title": "Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14306"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-66678",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Justin Kruit",
      "product": "Advanced Custom Fields: Font Awesome Field",
      "cwe": "CWE-862",
      "title": "WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66678"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-25403",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Ultimate Store Kit Elementor Addons",
      "cwe": "CWE-862",
      "title": "WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25403"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-14829",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps",
      "cwe": "CWE-284",
      "title": "Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14829"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-66439",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeRocket",
      "product": "Advanced AJAX Product Filters",
      "cwe": "CWE-79",
      "title": "WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66439"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-66440",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XplodedThemes",
      "product": "WPIDE – File Manager & Code Editor",
      "cwe": "CWE-79",
      "title": "WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66440"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-66457",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@msykes",
      "product": "Events Manager",
      "cwe": "CWE-79",
      "title": "WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66457"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-66663",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Passionate Programmer Peter",
      "product": "WP Data Access",
      "cwe": "CWE-79",
      "title": "WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66663"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-66664",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEO Squirrly",
      "product": "SEO Plugin by Squirrly SEO",
      "cwe": "CWE-79",
      "title": "WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66664"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-71435",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71435"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2025-15028",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpwax",
      "product": "FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More",
      "cwe": "CWE-79",
      "title": "FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15028"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-71497",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jhy",
      "product": "jsoup",
      "cwe": "CWE-79",
      "title": "jsoup: Cleaner may expose markup with custom raw-text elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71497"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-15256",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ninja Forms",
      "cwe": "CWE-74",
      "title": "Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15256"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2025-14779",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00188,
      "epss_percentile": 0.08743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server",
      "cwe": "CWE-281",
      "title": "Improper Access Control via Secret Type Management API in WSO2 Identity Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14779"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-19058",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FoundationAgents",
      "product": "MetaGPT",
      "cwe": "CWE-74",
      "title": "FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19058"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-19060",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FoundationAgents",
      "product": "MetaGPT",
      "cwe": "CWE-74",
      "title": "FoundationAgents MetaGPT code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19060"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-18597",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Services API",
      "cwe": "CWE-918",
      "title": "Blind SSRF on Foxit PDF Services API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18597"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-65517",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scott Paterson",
      "product": "Easy PayPal Buy Now Button",
      "cwe": "CWE-79",
      "title": "WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65517"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-66699",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan, Inc.",
      "product": "Dokan",
      "cwe": "CWE-862",
      "title": "WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66699"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-66701",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Profile Builder",
      "cwe": "CWE-862",
      "title": "WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66701"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-14547",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Estatik Real Estate Plugin",
      "cwe": "CWE-287",
      "title": "Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14547"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-19061",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Insta",
      "product": "InstaKNXServiceApp",
      "cwe": "CWE-345",
      "title": "Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList data authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19061"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-28082",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28082"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-28141",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "NextGEN Gallery",
      "cwe": "CWE-79",
      "title": "WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28141"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-28143",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Forminator",
      "cwe": "CWE-79",
      "title": "WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28143"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-28177",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daniel Iser",
      "product": "Popup Maker",
      "cwe": "CWE-79",
      "title": "WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28177"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-61961",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "EmbedPress",
      "cwe": "CWE-79",
      "title": "WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61961"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-61963",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-79",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61963"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-61964",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Ninja Tables",
      "cwe": "CWE-79",
      "title": "WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61964"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-61982",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jp-secure",
      "product": "SiteGuard WP Plugin",
      "cwe": "CWE-79",
      "title": "WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61982"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-65509",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpDataTables",
      "product": "wpDataTables",
      "cwe": "CWE-79",
      "title": "WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65509"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-65513",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-79",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65513"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-65515",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AffiliateWP",
      "product": "AffiliateWP",
      "cwe": "CWE-79",
      "title": "WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65515"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-65544",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rajat Varlani",
      "product": "Super Socializer",
      "cwe": "CWE-79",
      "title": "WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65544"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-65545",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jordy Meow",
      "product": "AI Engine",
      "cwe": "CWE-79",
      "title": "WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65545"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-65560",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Property Hive",
      "product": "Houzez Property Feed",
      "cwe": "CWE-79",
      "title": "WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65560"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-65565",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ays Pro",
      "product": "Survey Maker",
      "cwe": "CWE-79",
      "title": "WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65565"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-45572",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-94",
      "title": "Decidim: HTML content blocks allow stored script execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45572"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-12584",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payment Gateway for Redsys & WooCommerce Lite",
      "cwe": null,
      "title": "Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12584"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2025-11850",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server",
      "cwe": "CWE-639",
      "title": "Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11850"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-66696",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Gutenberg Blocks by Kadence Blocks",
      "cwe": "CWE-201",
      "title": "WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66696"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-7867",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-863",
      "title": "Udisks2: udisks2: local privilege escalation via as-user option spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7867"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2024-10302",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Control Plane",
      "cwe": "CWE-20",
      "title": "Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-10302"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-28179",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.0698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Damian Góra",
      "product": "FiboSearch",
      "cwe": "CWE-79",
      "title": "WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28179"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2025-13736",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.06867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server as Key Manager",
      "cwe": "CWE-203",
      "title": "Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13736"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-71555",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "THM-Health",
      "product": "PILOS",
      "cwe": "CWE-1022",
      "title": "PILOS: Reverse tabnabbing in room description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71555"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-71438",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-1321",
      "title": "Mermaid configuration APIs allow prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71438"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-64591",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.06103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Avoid WARNING in sva unbind path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64591"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-64593",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.0614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: do not trim a device which is not writeable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64593"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-64594",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.0614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_fs: initialize reset_work at allocation time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64594"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-64602",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.0614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: adc: spear: Initialize completion before requesting IRQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64602"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-64604",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.06139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64604"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-11588",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "EONSR AEO Agent",
      "cwe": "CWE-79",
      "title": "EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11588"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-28178",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codesupplyco",
      "product": "Powerkit",
      "cwe": "CWE-79",
      "title": "WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28178"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-10599",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Integrate PhonePe with WooCommerce",
      "cwe": "CWE-345",
      "title": "Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10599"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-70640",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-476",
      "title": "llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70640"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2025-9266",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themegrill",
      "product": "Accelerate",
      "cwe": "CWE-862",
      "title": "Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9266"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-5158",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpxpo",
      "product": "Post Grid Gutenberg Blocks – PostX",
      "cwe": "CWE-79",
      "title": "PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5158"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-5391",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
      "cwe": "CWE-79",
      "title": "LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5391"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-18501",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stiofansisland",
      "product": "UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP",
      "cwe": "CWE-79",
      "title": "UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18501"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-12501",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.0526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Travel Engine",
      "cwe": "CWE-345",
      "title": "WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12501"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-14936",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.0526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Membership",
      "cwe": "CWE-345",
      "title": "Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14936"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-71498",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.0525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uhop",
      "product": "node-re2",
      "cwe": "CWE-125",
      "title": "node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71498"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-64589",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: core: fix NULL-deref on adapter registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64589"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-64590",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64590"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-64592",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv: mm: Unconditionally sfence.vma for spurious fault",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64592"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-64603",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: intel-hid: Protect ACPI notify handler against recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64603"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-66690",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66690"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-66694",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thrive Themes Coupon",
      "product": "Thrive Architect",
      "cwe": "CWE-79",
      "title": "WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66694"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-66702",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rank Math SEO",
      "product": "Rank Math SEO",
      "cwe": "CWE-79",
      "title": "WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66702"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-66707",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Facebook",
      "product": "Facebook for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66707"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-64596",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.05133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64596"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-41861",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudFoundry Foundation",
      "product": "BOSH",
      "cwe": "CWE-22",
      "title": "Arbitrary Root File Write via Path Traversal in BOSH agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41861"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-16316",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OMICRON electronics GmbH",
      "product": "OMICRON StationGuard",
      "cwe": "CWE-20",
      "title": "Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16316"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-70628",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-190",
      "title": "FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70628"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2025-15678",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Nexter Blocks",
      "cwe": "CWE-79",
      "title": "Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15678"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-55978",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SecureAge",
      "product": "CatchPulse",
      "cwe": "CWE-284",
      "title": "Improper access control vulnerability in CatchPulse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55978"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-66706",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mark Jaquith",
      "product": "Subscribe to Comments",
      "cwe": "CWE-79",
      "title": "WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66706"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-66705",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Facebook",
      "product": "Facebook for WordPress",
      "cwe": "CWE-79",
      "title": "WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66705"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-64595",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.0425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64595"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-18967",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-294",
      "title": "Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18967"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-48081",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-79",
      "title": "OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48081"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-55980",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SecureAge",
      "product": "CatchPulse",
      "cwe": "CWE-121",
      "title": "Denial-of-service vulnerability in CatchPulse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55980"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-1289",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Revit",
      "cwe": "CWE-416",
      "title": "PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1289"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-11803",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Revit",
      "cwe": "CWE-125",
      "title": "PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11803"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-11361",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Formidable Forms",
      "cwe": "CWE-345",
      "title": "Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11361"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-19054",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lspace-io",
      "product": "lspace-server",
      "cwe": "CWE-22",
      "title": "Lspace-io lspace-server Repositories File API repository.ts deleteFile path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19054"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-64993",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00139,
      "epss_percentile": 0.0374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "RVTools",
      "cwe": "CWE-295",
      "title": "Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64993"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-43627",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-190",
      "title": "llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43627"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-66688",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "Ultimate Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66688"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-66703",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "MailOptin",
      "cwe": "CWE-79",
      "title": "WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66703"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-13703",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SEO Redirection Plugin",
      "cwe": "CWE-284",
      "title": "SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13703"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-19046",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NocteDefensor",
      "product": "LudusMCP",
      "cwe": "CWE-22",
      "title": "NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19046"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-70631",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-908",
      "title": "FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70631"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-43622",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-762",
      "title": "llama.cpp b1886–b7445 Double Free via llama-android.cpp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43622"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-70638",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-190",
      "title": "llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70638"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-7406",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Revit",
      "cwe": "CWE-822",
      "title": "BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7406"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-8166",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logo Software Industry and Trade Inc.",
      "product": "e-Logo Purchasing Portal",
      "cwe": "CWE-79",
      "title": "Stored XSS in Logo Software's e-Logo Purchasing Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8166"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-16537",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Slick Slider",
      "cwe": "CWE-79",
      "title": "Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16537"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-18395",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Child Pages Card",
      "cwe": "CWE-79",
      "title": "Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18395"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-55979",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SecureAge",
      "product": "CatchPulse",
      "cwe": "CWE-284",
      "title": "Improper access control check in CatchPulse's named pipe communication interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55979"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-70629",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-908",
      "title": "FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70629"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-70630",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-908",
      "title": "FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70630"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-71325",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-653",
      "title": "Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71325"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-18367",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00131,
      "epss_percentile": 0.03165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sophos",
      "product": "Sophos Endpoint for macOS",
      "cwe": "CWE-285",
      "title": "A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18367"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-8325",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Revit",
      "cwe": "CWE-787",
      "title": "PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8325"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-70639",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-476",
      "title": "llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cpp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70639"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2025-12627",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server",
      "cwe": "CWE-613",
      "title": "Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12627"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-70556",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hubzilla",
      "product": "Hubzilla",
      "cwe": "CWE-352",
      "title": "Hubzilla version prior to 11.4 CSRF via OAuth2 /authorize Endpoint App Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70556"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-19143",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19143"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-12901",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GetPaid",
      "cwe": "CWE-345",
      "title": "GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12901"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-15147",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Five Star Restaurant Reservations",
      "cwe": "CWE-345",
      "title": "Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15147"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-15152",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Hotel Booking",
      "cwe": "CWE-345",
      "title": "WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15152"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-15208",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RegistrationMagic",
      "cwe": "CWE-345",
      "title": "RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15208"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-64601",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64601"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-66686",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vladimir Garagulya",
      "product": "Plugins Garbage Collector (Database Cleanup)",
      "cwe": "CWE-352",
      "title": "WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66686"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-66732",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eukaryot",
      "product": "sonic3air",
      "cwe": "CWE-346",
      "title": "Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66732"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-64587",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ethernet: arc: emac: quiesce interrupts before requesting IRQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64587"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-14204",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Google Authenticator",
      "cwe": "CWE-352",
      "title": "Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14204"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-14313",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PeproDev WooCommerce Receipt Uploader",
      "cwe": "CWE-352",
      "title": "PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14313"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-64585",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "can: esd_usb: kill anchored URBs before freeing netdevs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64585"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-19108",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.02215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "libiec61850",
      "cwe": "CWE-119",
      "title": "MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19108"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2024-8995",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-613",
      "title": "Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-8995"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-64588",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse-uring: fix data races on ring->ready",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64588"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-64599",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: amlogic - avoid double cleanup in meson_crypto_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64599"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-64652",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cli",
      "product": "cli",
      "cwe": "CWE-201",
      "title": "GitHub CLI: Partial token disclosure in `gh auth status` output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64652"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-64583",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64583"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-64584",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_midi: cancel pending IN work before freeing the midi object",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64584"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-7405",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Revit",
      "cwe": "CWE-125",
      "title": "TIF File Parsing Out-of-Bounds Read in certain Autodesk products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7405"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-66681",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jeff Farthing",
      "product": "Theme My Login",
      "cwe": "CWE-352",
      "title": "WordPress theme My Login plugin <= 7.1.14 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66681"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-0637",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-532",
      "title": "Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0637"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-71430",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uhop",
      "product": "node-re2",
      "cwe": "CWE-617",
      "title": "node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71430"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-15246",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RealHomes Memberships",
      "cwe": "CWE-345",
      "title": "RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15246"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-18915",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TÜBİTAK BİLGEM Software Technologies Research Institute",
      "product": "eta-otp-lock",
      "cwe": "CWE-214",
      "title": "Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18915"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-28172",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Data443 Risk Mitigation, Inc.",
      "product": "Tracking Code Manager",
      "cwe": "CWE-352",
      "title": "WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28172"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2025-13394",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13394"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-19139",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19139"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-15599",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00088,
      "epss_percentile": 0.00466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TÜBİTAK BİLGEM Software Technologies Research Institute",
      "product": "pardus-domain-joiner",
      "cwe": "CWE-283",
      "title": "Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15599"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-18909",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ELAN Microelectronics Corp.",
      "product": "ELAN Smart-Pad",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18909"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2012-4681",
      "detail": "EXPLOIT PUBLISHED — CVE-2012-4681. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-15107",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-15107. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-22205",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-22205 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-43890",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-43890 (Microsoft App Installer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-30190",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-30190 (Microsoft Windows 10 Version 1809). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-40684",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-40684 (Fortinet FortiOS, FortiProxy, FortiSwitchManager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-42753",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-42753 (Red Hat Enterprise Linux 7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10634",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10634 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10639 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10646",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10646 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10647",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10647 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10652",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10652 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10653 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10670",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10670 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12605",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12605 (Eclipse Foundation Eclipse GlassFish). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16746",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16746 (Unknown MultiVendorX). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16940",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16940 (Unknown Custom Fields). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16981",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16981 (Unknown DHL Shipping Germany for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18958",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18958 (imranrisal-dev Student-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18959",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18959 (yushine InnoShop). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43997 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43998 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43999",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43999 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44001",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44001 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44004",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44004 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44005",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44005 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44006",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44006 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44007 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44008",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44008 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44009",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44009 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44210",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44210 (kata-containers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45411 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47429",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47429 (vitest-dev vitest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54656",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54656 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54690",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54690 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54894",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54894 (ueberauth guardian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55389",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55389 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55415",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55415 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55733",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55733 (ueberauth guardian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55734",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55734 (ueberauth guardian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55735",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55735 (ueberauth guardian). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64827",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64827 (Telenia Software TVox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64828 (Froiden TableTrack). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67623",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67623 (mistralai mistral-vibe). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69111",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69111 (milvus-io milvus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70615",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70615 (boringproxy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70616",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70616 (boringproxy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7656",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7656 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-8037",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-8037 (Progress Software LoadMaster). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-42753",
      "detail": "RESCORED — CVE-2023-42753 (Red Hat Enterprise Linux 7). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-5090",
      "detail": "RESCORED — CVE-2023-5090 (Red Hat Enterprise Linux 8). CVSS 6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-0646",
      "detail": "RESCORED — CVE-2024-0646 (kernel). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-1488",
      "detail": "RESCORED — CVE-2024-1488 (unbound). CVSS 8 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-21549",
      "detail": "RESCORED — CVE-2024-21549 (spatie/browsershot). CVSS 7.7 → 6.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10634",
      "detail": "RESCORED — CVE-2026-10634 (zephyrproject zephyr). CVSS 4.8 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10643",
      "detail": "RESCORED — CVE-2026-10643 (zephyrproject zephyr). CVSS 8.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10652",
      "detail": "RESCORED — CVE-2026-10652 (zephyrproject zephyr). CVSS 4.8 → 7.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10653",
      "detail": "RESCORED — CVE-2026-10653 (zephyrproject zephyr). CVSS 6.4 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-11714",
      "detail": "RESCORED — CVE-2026-11714 (IBM WebSphere Application Server - Liberty). CVSS 8.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16108",
      "detail": "RESCORED — CVE-2026-16108 (Red Hat Build of Keycloak). CVSS 4.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18968",
      "detail": "RESCORED — CVE-2026-18968 (ttttonyhe OBlog). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18969",
      "detail": "RESCORED — CVE-2026-18969 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18970",
      "detail": "RESCORED — CVE-2026-18970 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47429",
      "detail": "RESCORED — CVE-2026-47429 (vitest-dev vitest). CVSS 9.8 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7656",
      "detail": "RESCORED — CVE-2026-7656 (zephyrproject zephyr). CVSS 8.1 → 6.8 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
