{
  "day": "2026-08-07",
  "boundary": "UTC calendar day",
  "published_count": 215,
  "by_severity": {
    "CRITICAL": 25,
    "HIGH": 79,
    "MEDIUM": 92,
    "LOW": 19
  },
  "kev_count": 1,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-8037",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.99311,
      "epss_percentile": 0.99936,
      "kev": true,
      "kev_due_at": "2026-08-10",
      "vendor": "Progress Software",
      "product": "LoadMaster",
      "cwe": "CWE-77",
      "title": "OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8037"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-19243",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0161,
      "epss_percentile": 0.73972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-77",
      "title": "HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19243"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-61808",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01379,
      "epss_percentile": 0.69917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-306",
      "title": "LightRAG: Missing Authentication for Critical API Functions in Default Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61808"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-64638",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00894,
      "epss_percentile": 0.56697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress",
      "product": "WordPress",
      "cwe": "CWE-79",
      "title": "WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64638"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-71558",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00715,
      "epss_percentile": 0.50903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-843",
      "title": "Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71558"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2022-4995",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00687,
      "epss_percentile": 0.49903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaver Network Co., Ltd.",
      "product": "E-cology 9.0",
      "cwe": "CWE-434",
      "title": "Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-4995"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-69207",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00653,
      "epss_percentile": 0.48523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-1333",
      "title": "Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69207"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-19264",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00631,
      "epss_percentile": 0.47537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitroomhq",
      "product": "postiz-app",
      "cwe": "CWE-22",
      "title": "Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19264"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-71559",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00593,
      "epss_percentile": 0.45754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-502",
      "title": "Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71559"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-71560",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00554,
      "epss_percentile": 0.43853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-125",
      "title": "Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71560"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-11430",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00506,
      "epss_percentile": 0.41112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trilby Media",
      "product": "grav-plugin-scheduler-webhook",
      "cwe": "CWE-303",
      "title": "Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11430"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-16258",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00472,
      "epss_percentile": 0.38986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ajax Search Lite",
      "cwe": "CWE-502",
      "title": "Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16258"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-54210",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00466,
      "epss_percentile": 0.38587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-787",
      "title": "TeamDavid: Buffer Overflow in file names of file upload functionalities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54210"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-54212",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00466,
      "epss_percentile": 0.38587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-787",
      "title": "TeamDavid: Buffer Overflow in JSON-parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54212"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-56818",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00465,
      "epss_percentile": 0.38567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-401",
      "title": "Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56818"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-16637",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00457,
      "epss_percentile": 0.38025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OPeNDAP Inc.",
      "product": "hyrax-docker",
      "cwe": "CWE-201",
      "title": "OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16637"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-54213",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00446,
      "epss_percentile": 0.37272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-284",
      "title": "TeamDavid: Denial of Service via endpoint 'internalRestart'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54213"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-54211",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-787",
      "title": "TeamDavid: Buffer Overflow in multiple form data parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54211"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-67585",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DivvyPayHQ",
      "product": "absinthe_federation",
      "cwe": "CWE-770",
      "title": "Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67585"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-47659",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aehrc",
      "product": "pathling",
      "cwe": "CWE-22",
      "title": "Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47659"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-47661",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aehrc",
      "product": "pathling",
      "cwe": "CWE-22",
      "title": "Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47661"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-68772",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenML",
      "product": "ZenML",
      "cwe": "CWE-502",
      "title": "ZenML 0.94.6 Remote Code Execution via CloudpickleMaterializer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68772"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-66494",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66494"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-17603",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-94",
      "title": "Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17603"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-15972",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-770",
      "title": "Unauthenticated denial of service via unbounded external gRPC connection acceptance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15972"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-54208",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-20",
      "title": "TeamDavid: Arbitrary File Write leading to Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54208"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-66914",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00379,
      "epss_percentile": 0.31145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seblod.com",
      "product": "SEBLOD extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66914"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-50540",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00378,
      "epss_percentile": 0.31055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kata-containers",
      "product": "kata-containers",
      "cwe": "CWE-20",
      "title": "Kata Containers: Config Path Annotation Arbitrary File Loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50540"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-66492",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Commander extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66492"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-65819",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gopacket",
      "product": "gopacket",
      "cwe": "CWE-125",
      "title": "gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65819"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-62992",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.2961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smarty-php",
      "product": "smarty",
      "cwe": "CWE-22",
      "title": "Smarty: Symlink path traversal out of trusted directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62992"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-46405",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbao",
      "product": "openbao",
      "cwe": "CWE-770",
      "title": "OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46405"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-46409",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openyak",
      "product": "openyak",
      "cwe": "CWE-94",
      "title": "OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46409"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-20337",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV ZIP File Format Processing Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20337"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-15215",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Subscriptions for WooCommerce",
      "cwe": "CWE-269",
      "title": "Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15215"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-71557",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.28135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-git",
      "product": "go-git",
      "cwe": "CWE-22",
      "title": "go-git: Malicious reference names may modify files outside the reference storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71557"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-62996",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smarty-php",
      "product": "smarty",
      "cwe": "CWE-22",
      "title": "Smarty Security stream restriction bypass through stream: resource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62996"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-49007",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.2768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "F689",
      "cwe": "CWE-798",
      "title": "Information leakage vulnerability in ZTE F689 product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49007"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-48039",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pipeboard-co",
      "product": "meta-ads-mcp",
      "cwe": "CWE-287",
      "title": "Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48039"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-58375",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-89",
      "title": "Frappe has potential SQL Injection due to missing validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58375"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-16263",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Maps",
      "cwe": "CWE-22",
      "title": "WP Maps < 4.9.7 - Subscriber+ Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16263"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-48047",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xwiki",
      "product": "xwiki-platform",
      "cwe": "CWE-24",
      "title": "XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48047"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-12071",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-601",
      "title": "TeamDavid: Header Injection leading to Open Redirect via URL-encoded characters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12071"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-54214",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-601",
      "title": "TeamDavid: Header Injection through the 'cType' URL parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54214"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-19229",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Clothing Store",
      "cwe": "CWE-200",
      "title": "SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19229"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-19017",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-862",
      "title": "Consul vulnerable to partial arbitrary file read via Vault Connect CA provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19017"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-20338",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-415",
      "title": "ClamAV ZIP File Format Processing Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20338"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-20339",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-190",
      "title": "ClamAV PESpin File Format Processing Integer Overflow Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20339"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-20345",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-121",
      "title": "ClamAV GPT File Format Processing Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20345"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-20346",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-125",
      "title": "ClamAV PDF File Format Processing Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20346"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-20347",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-125",
      "title": "ClamAV Mach-O File Format Processing Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20347"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-20348",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV XAR File Format Processing Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20348"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-54204",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-20",
      "title": "TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54204"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-54201",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-862",
      "title": "TeamDavid: Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54201"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-54203",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0032,
      "epss_percentile": 0.2483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-200",
      "title": "TeamDavid: Memory Leak leaking sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54203"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2025-63235",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the connection or send a CONNACK but fail to close the session or deallocate internal resources. This behavior allows an attacker to create numerous half-open connections that consume memory and file descriptors indefinitely, potentially triggering the Linux OOM killer and causing a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63235"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-71851",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00317,
      "epss_percentile": 0.24511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brix",
      "product": "crypto-js",
      "cwe": "CWE-331",
      "title": "crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71851"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-56793",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-287",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56793"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-66491",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Commander extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66491"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-66493",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Commander extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66493"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-14365",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.23955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker – Appointment Booking and Scheduler System",
      "cwe": "CWE-862",
      "title": "TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14365"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-47660",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.2381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aehrc",
      "product": "pathling",
      "cwe": "CWE-522",
      "title": "Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47660"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-17593",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository",
      "cwe": "CWE-470",
      "title": "Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17593"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-45808",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbao",
      "product": "openbao",
      "cwe": "CWE-863",
      "title": "OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45808"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-48094",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.2316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dartiss",
      "product": "shareopenly",
      "cwe": "CWE-79",
      "title": "ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48094"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-54202",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-36",
      "title": "TeamDavid: Path Traversal in the archive creation functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54202"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-56794",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-23",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56794"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-52879",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-400",
      "title": "Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52879"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-52880",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-400",
      "title": "Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52880"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-17599",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-620",
      "title": "Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17599"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-17597",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-918",
      "title": "Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17597"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-19015",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.2188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-770",
      "title": "Uncontrolled resource consumption in the Consul Connect CA roots endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19015"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-19113",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.2188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-400",
      "title": "Unauthenticated denial of service via unbounded request body processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19113"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-19082",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.2183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TONYC",
      "product": "Imager",
      "cwe": "CWE-125",
      "title": "Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19082"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-70561",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TestLinkOpenSourceTRMS",
      "product": "TestLink",
      "cwe": "CWE-639",
      "title": "TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70561"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-71556",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-git",
      "product": "go-git",
      "cwe": "CWE-59",
      "title": "go-git: Worktree operations may follow symlinks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71556"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-69127",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.2173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-497",
      "title": "Kirby: System path exposure from error messages in the REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69127"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-66062",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.2173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "kit",
      "cwe": "CWE-1333",
      "title": "SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66062"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-71848",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-407",
      "title": "Hono: Algorithmic Complexity DoS in Language Middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71848"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-54209",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-125",
      "title": "TeamDavid: Buffer Overflow in 'editini' function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54209"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-17595",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.2124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-497",
      "title": "Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17595"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-14364",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.21091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker – Appointment Booking and Scheduler System",
      "cwe": "CWE-640",
      "title": "TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14364"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-54216",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-79",
      "title": "TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54216"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-54338",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterhub",
      "product": "jupyterhub",
      "cwe": "CWE-400",
      "title": "JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54338"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-19210",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Photo Share Website",
      "cwe": "CWE-284",
      "title": "SourceCodester Photo Share Website ajax.php save_upload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19210"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-54205",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-20",
      "title": "TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54205"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-54206",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-20",
      "title": "TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54206"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-54207",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-20",
      "title": "TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54207"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-47249",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-400",
      "title": "Klever-Go KVM: Hash-array amplification in P2P resolver request handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47249"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-52878",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-476",
      "title": "Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52878"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-62295",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-20",
      "title": "HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62295"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-62296",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-20",
      "title": "HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62296"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-66059",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-863",
      "title": "Frappe: Field-level permission bypass via Document Follow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66059"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-48097",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0x5t4l1n",
      "product": "NexTOR_IP_CHANGER",
      "cwe": "CWE-78",
      "title": "NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48097"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-19208",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "WonderTrader",
      "cwe": "CWE-840",
      "title": "WonderTrader TraderDD.cpp queryTrades behavioral workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19208"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-19244",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00272,
      "epss_percentile": 0.1967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-266",
      "title": "HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19244"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-54218",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-321",
      "title": "TeamDavid: Weak Cryptography and Insecure Password Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54218"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-54215",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-601",
      "title": "TeamDavid: Open Redirect via the 'replyUrl' parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54215"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-19212",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.19392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "WonderTrader",
      "cwe": "CWE-453",
      "title": "WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19212"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-14205",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Events Manager",
      "cwe": "CWE-287",
      "title": "WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14205"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-49343",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-400",
      "title": "Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49343"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-19196",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Photo Share Website",
      "cwe": "CWE-74",
      "title": "SourceCodester Photo Share Website ajax.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19196"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-19211",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Photo Share Website",
      "cwe": "CWE-74",
      "title": "SourceCodester Photo Share Website ajax.php signup sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19211"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-19231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Doctors Appointment System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19231"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-54199",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-20",
      "title": "TeamDavid: Header Injection through request body in link storing functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54199"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-64637",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.18135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-269",
      "title": "Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64637"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-19014",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-770",
      "title": "Uncontrolled resource consumption in the Consul Connect authorization endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19014"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-48169",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonai-platform",
      "cwe": "CWE-639",
      "title": "PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48169"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-14943",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content",
      "cwe": "CWE-200",
      "title": "Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14943"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-15816",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15816"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-66000",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00259,
      "epss_percentile": 0.17754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-863",
      "title": "Frappe: Unrestricted access to Document Follow APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66000"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-54217",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-20",
      "title": "TeamDavid: Stored XSS in web application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54217"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-71847",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby",
      "product": "json",
      "cwe": "CWE-416",
      "title": "Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71847"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-17598",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-915",
      "title": "Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17598"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-47364",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.1684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datadog",
      "product": "Android App",
      "cwe": "CWE-200",
      "title": "In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47364"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-48170",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0025,
      "epss_percentile": 0.16699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thomaspoignant",
      "product": "scim-patch",
      "cwe": "CWE-1321",
      "title": "scimPatch vulnerable to prototype pollution via unfiltered keys in patch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48170"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-19012",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.1597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-476",
      "title": "Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19012"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-47127",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ghostfolio",
      "product": "ghostfolio",
      "cwe": "CWE-862",
      "title": "Ghostfolio has a Stripe subscription bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47127"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-54200",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.1576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-73",
      "title": "TeamDavid: Local File Inclusion via the form field 'scjob'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54200"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-16038",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0024,
      "epss_percentile": 0.15337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MStore API",
      "cwe": "CWE-862",
      "title": "MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16038"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-66838",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-ecto",
      "product": "postgrex",
      "cwe": "CWE-89",
      "title": "SQL injection via the :comment option in Postgrex.stream/4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66838"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-61477",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0024,
      "epss_percentile": 0.15356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-93",
      "title": "Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61477"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-47662",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.1531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aehrc",
      "product": "pathling",
      "cwe": "CWE-20",
      "title": "Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47662"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-47663",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aehrc",
      "product": "pathling",
      "cwe": "CWE-285",
      "title": "Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47663"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-17596",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-79",
      "title": "Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17596"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-17594",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-863",
      "title": "Nexus Repository 3 - Authorization Bypass in Repository Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17594"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-64636",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.15029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-89",
      "title": "An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64636"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-71849",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00236,
      "epss_percentile": 0.14791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-200",
      "title": "Hono: Proxy Helper does not remove response headers listed in the `Connection` header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71849"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-14644",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-843",
      "title": "Nexus Repository 3 - Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14644"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-12070",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobit Laboratories AG",
      "product": "TeamDavid",
      "cwe": "CWE-73",
      "title": "TeamDavid: Arbitrary File Deletion via form field 'scjob'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12070"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-16265",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Maps",
      "cwe": "CWE-400",
      "title": "WP Maps < 4.9.7 - Subscriber+ Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16265"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-11907",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xwp",
      "product": "Stream – Activity Log & Audit Trail",
      "cwe": "CWE-862",
      "title": "Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11907"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-16030",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MStore API",
      "cwe": "CWE-287",
      "title": "MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16030"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-66058",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.1348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-639",
      "title": "Frappe: Unrestricted access to a Document Follow API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66058"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-15361",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Content Views",
      "cwe": "CWE-89",
      "title": "Content Views < 4.5 - Subscriber+ SQL Injection via preview_request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15361"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-19246",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00221,
      "epss_percentile": 0.12975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-918",
      "title": "HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19246"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-48026",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "treeverse",
      "product": "lakeFS",
      "cwe": "CWE-79",
      "title": "lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48026"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-59717",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-601",
      "title": "Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59717"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-19213",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00216,
      "epss_percentile": 0.12297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "WonderTrader",
      "cwe": "CWE-840",
      "title": "WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19213"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-17601",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.1221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-862",
      "title": "Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17601"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-17600",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-613",
      "title": "Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17600"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-19016",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-22",
      "title": "Authorization bypass for session deletion in the transaction API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19016"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-19207",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.11519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Company Visitor Management System",
      "cwe": "CWE-79",
      "title": "PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19207"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-16041",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MStore API",
      "cwe": "CWE-862",
      "title": "MStore API < 4.21.0 - Unauthenticated Product Review Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16041"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-15570",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vestel",
      "product": "Telefunken TE24553B45V2DZ Smart TV",
      "cwe": "CWE-918",
      "title": "Improper URL Scheme and Destination Validation in SmartCenter browserseturl Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15570"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-15359",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Templately",
      "cwe": "CWE-862",
      "title": "Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15359"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-16039",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MStore API",
      "cwe": "CWE-639",
      "title": "MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16039"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2025-71409",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.10208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATN-B1",
      "product": "CPDLC",
      "cwe": "CWE-306",
      "title": "No Authentication for Very High Frequency Data Link messages used in CPDLC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71409"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-19209",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Photo Share Website",
      "cwe": "CWE-79",
      "title": "SourceCodester Photo Share Website index.php home cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19209"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-19230",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Photo Share Website",
      "cwe": "CWE-79",
      "title": "SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19230"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2025-71410",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.10013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATN-B1",
      "product": "CPDLC",
      "cwe": "CWE-770",
      "title": "Malicious Link Control Frames Can Cause Loss of CPDLC Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71410"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2025-71411",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.10012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATN-B1",
      "product": "CPDLC",
      "cwe": "CWE-770",
      "title": "In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultaneously",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71411"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2025-71413",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.10013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATN-B1",
      "product": "CPDLC",
      "cwe": "CWE-754",
      "title": "In CPDLC, Malformed or Out of Sequence Frames Can Cause Resets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71413"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-12261",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk/nltk",
      "cwe": "CWE-284",
      "title": "Improper Access Control in nltk/nltk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12261"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-44964",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datadog",
      "product": "Android App",
      "cwe": "CWE-441",
      "title": "In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an arbitrary on-call page ID, and an arbitrary Intent to run inside the Datadog process. This requires: A malicious application co-installed on the victim's device. An active Datadog session in the Android app. Impact: After a single tap on the Acknowledge button, the app sends a forged on-call acknowledgement to the backend under the victim's session, launches the attacker-supplied Intent from within the Datadog process (reaching otherwise non-exported components), and turns on the screen while dismissing the keyguard.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44964"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2025-71412",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATN-B1",
      "product": "CPDLC",
      "cwe": "CWE-754",
      "title": "In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71412"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-16027",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.0826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revenue Administration",
      "product": "E-Signature",
      "cwe": "CWE-918",
      "title": "Unauthenticated WebSocket-to-XAdES SSRF in Revenue Administration's E-Signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16027"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-47243",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00181,
      "epss_percentile": 0.07959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kata-containers",
      "product": "kata-containers",
      "cwe": "CWE-22",
      "title": "Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47243"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-49008",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "F689",
      "cwe": "CWE-321",
      "title": "Integrity‑check credential leakage vulnerability in an application function of ZTE F689 product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49008"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-47361",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datadog",
      "product": "Android App",
      "cwe": "CWE-926",
      "title": "In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI chat notification), with no check on the caller's identity or ownership of the conversation. This requires a malicious application co-installed on the victim's device. Impact: A co-installed application can silently dismiss the victim's Bits AI chat notification. No chat content is exposed; conversation data remains server-authentication gated and is never returned to the caller.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47361"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-47362",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datadog",
      "product": "Android App",
      "cwe": "CWE-922",
      "title": "In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history). Impact: Any actor able to bypass the app sandbox can read these databases in plaintext.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47362"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-48007",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "element-hq",
      "product": "element-call",
      "cwe": "CWE-200",
      "title": "Element Call reports full URLs of visited pages to analytics server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48007"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-71850",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-488",
      "title": "Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71850"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-19206",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00164,
      "epss_percentile": 0.06132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "libiec61850",
      "cwe": "CWE-119",
      "title": "MZ Automation libiec61850 ASDU Element sv_subscriber.c SVReceiver_stopThreadless heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19206"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-9031",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.0601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer A6 v4",
      "cwe": "CWE-20",
      "title": "Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9031"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-48093",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dartiss",
      "product": "code-embed",
      "cwe": "CWE-79",
      "title": "Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48093"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-15032",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Comments",
      "cwe": "CWE-79",
      "title": "wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15032"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-15214",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Subscriptions for WooCommerce",
      "cwe": "CWE-639",
      "title": "Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15214"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-37171",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-863",
      "title": "A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37171"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-15970",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-647",
      "title": "L7 intention authorization bypass via custom public listener",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15970"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-16262",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Estatik Real Estate Plugin",
      "cwe": "CWE-352",
      "title": "Estatik < 4.3.3 - Login CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16262"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-71381",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Genuine Software Integrity Service",
      "cwe": "CWE-863",
      "title": "Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71381"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-12801",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefic",
      "product": "Ultra Addons for Contact Form 7",
      "cwe": "CWE-79",
      "title": "Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12801"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-11425",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00156,
      "epss_percentile": 0.05277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Domoticz",
      "product": "Domoticz",
      "cwe": "CWE-79",
      "title": "Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert Device Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11425"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-14331",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.0461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Subscribe2",
      "cwe": "CWE-79",
      "title": "Subscribe2 < 10.46 - Reflected XSS via email Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14331"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-49006",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "F689",
      "cwe": "CWE-321",
      "title": "TLS credential leakage vulnerability in ZTE F689 product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49006"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-46358",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbao",
      "product": "openbao",
      "cwe": "CWE-532",
      "title": "OpenBao's Inline Auth Incorrectly Redacted Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46358"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-47664",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.0424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aehrc",
      "product": "pathling",
      "cwe": "CWE-20",
      "title": "Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and warehouse data poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47664"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-9169",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LUCID Vision Labs",
      "product": "Arena SDK",
      "cwe": "CWE-427",
      "title": "LUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9169"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-47363",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datadog",
      "product": "Android App",
      "cwe": "CWE-926",
      "title": "In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a malicious application co-installed on a device with the Datadog app installed, and an OAuth token the attacker is willing to load into the victim's app. Impact: A co-installed application can switch the victim's Datadog app to a session the attacker controls. This is an account-confusion issue; it does not by itself expose the victim's existing session or data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47363"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-19190",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StableBit",
      "product": "Scanner",
      "cwe": "CWE-266",
      "title": "StableBit Scanner ScannerService Scanner.Service.exe permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19190"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-48120",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mawww",
      "product": "kakoune",
      "cwe": "CWE-74",
      "title": "Kakoune has a Critical RCE via Autorestore Backup Filename Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48120"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-15245",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BNE Testimonials",
      "cwe": "CWE-79",
      "title": "BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15245"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-15386",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Meow Gallery",
      "cwe": "CWE-79",
      "title": "Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15386"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-48098",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0x5t4l1n",
      "product": "NexTOR_IP_CHANGER",
      "cwe": "CWE-78",
      "title": "NexTOR IP Changer Unsafely Uses sudo and shell=True",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48098"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-9030",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer A6 v4",
      "cwe": "CWE-362",
      "title": "Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9030"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-71870",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible large memory usage for large /ToUnicode streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71870"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-71852",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-834",
      "title": "pypdf: Possible long runtimes/large memory usage for large CID font width ranges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71852"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-48122",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shopify",
      "product": "ruby-lsp",
      "cwe": "CWE-78",
      "title": "Workspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48122"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-18497",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sean Barrett (nothings)",
      "product": "nothings stb",
      "cwe": "CWE-122",
      "title": "The nothings stb TrueType library contains a heap buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18497"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-64676",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kata-containers",
      "product": "kata-containers",
      "cwe": "CWE-862",
      "title": "Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64676"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-19245",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-200",
      "title": "HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19245"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-45198",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-822",
      "title": "GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45198"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-58262",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-345",
      "title": "Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58262"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-17435",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.0199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "File::Rotate::Simple",
      "cwe": "CWE-59",
      "title": "File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17435"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-62293",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-20",
      "title": "HAPI FHIR: Stored XSS in scan report via unescaped IG and profile titles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62293"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-49005",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00115,
      "epss_percentile": 0.01787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "F689",
      "cwe": "CWE-916",
      "title": "Root password hash exposure vulnerability in ZTE F689 product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49005"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-15148",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Events Manager",
      "cwe": "CWE-345",
      "title": "WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15148"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-66060",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-862",
      "title": "Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66060"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-66061",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-862",
      "title": "Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66061"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-44965",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datadog",
      "product": "Android App",
      "cwe": "CWE-926",
      "title": "In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a caller-supplied AppWidgetManager.EXTRA_APPWIDGET_ID and, when no deep-link destination is resolved, uses it to load the matching widget's stored session and automatically log in as that user. Because Android widget IDs are small sequential integers, a co-installed application can brute-force this value to find one that matches a widget configured on the victim's device. This requires: A malicious application co-installed on the victim's device. At least one of the six widgets configured on the victim's home screen. An active Datadog session cached locally. Impact: The matching configuration activity opens in the foreground under the victim's session and renders live infrastructure data. Exposure is limited to a visual side channel (e.g., screen recording or accessibility services); the calling application cannot programmatically read the rendered data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44965"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-19189",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Power Sofware",
      "product": "PowerISO",
      "cwe": "CWE-266",
      "title": "Power Sofware PowerISO Kernel Driver scdemu.sys privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19189"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-19193",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jiangmin",
      "product": "Antivirus",
      "cwe": "CWE-266",
      "title": "Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19193"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-19195",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "V-Secure",
      "product": "Jingyun Antivirus",
      "cwe": "CWE-266",
      "title": "V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19195"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-15211",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Subscriptions for WooCommerce",
      "cwe": "CWE-345",
      "title": "Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15211"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-15239",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple CAPTCHA with Cloudflare Turnstile",
      "cwe": "CWE-345",
      "title": "Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15239"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-66151",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "Global VPN Client",
      "cwe": "CWE-125",
      "title": "SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66151"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-19191",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StableBit",
      "product": "DrivePool",
      "cwe": "CWE-266",
      "title": "StableBit DrivePool DrivePoolService DrivePool.Service.exe permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19191"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-19192",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DeepCool",
      "product": "DisplayService",
      "cwe": "CWE-266",
      "title": "DeepCool DisplayService DeepCoolDisplayService.exe access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19192"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-49746",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-823",
      "title": "GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49746"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-18938",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18938"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-45204",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-476",
      "title": "GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45204"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-11743",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11743"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-11742",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00093,
      "epss_percentile": 0.00661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11742"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-19079",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00082,
      "epss_percentile": 0.00266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-367",
      "title": "Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19079"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-18184",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-18184. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-24682",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-24682. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-1086",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-1086 (Linux Kernel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-15674",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-15674 (Unknown Passster). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-56005",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-56005. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10524",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10524 (Unknown CoCart). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10599",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10599 (Unknown Integrate PhonePe with WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10773",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10773 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11361",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11361 (Unknown Formidable Forms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11976",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11976 (Unknown MonsterInsights Pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12501",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12501 (Unknown WP Travel Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12584 (Unknown Payment Gateway for Redsys & WooCommerce Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12901",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12901 (Unknown GetPaid). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13342",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13342 (Unknown Security Optimizer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13399",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13399 (Unknown Payment Plugins for PayPal WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14225 (Unknown Easy Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14306",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14306 (Unknown Tutor LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14812 (Unknown Premium SEO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14831",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14831 (Unknown Easy Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14842 (Unknown Events Made Easy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14936",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14936 (Unknown Simple Membership). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15147",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15147 (Unknown Five Star Restaurant Reservations). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15149",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15149 (Unknown WP Hotel Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15152",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15152 (Unknown WP Hotel Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15208",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15208 (Unknown RegistrationMagic). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15256",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15256 (Unknown Ninja Forms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16067",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16067 (Unknown Event Booking Manager for WooCommerce (Pro)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16619",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16619 (Unknown miniOrange 2FA). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16620 (Unknown WPC Name Your Price for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17032",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17032 (Unknown google-maps-easy-pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19058",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19058 (FoundationAgents MetaGPT). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19059",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19059 (FoundationAgents MetaGPT). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19060",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19060 (FoundationAgents MetaGPT). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19062",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19062 (chiuwingyan house). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19067",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19067 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19068",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19068 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19069",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19069 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19070",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19070 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19071",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19071 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19108",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19108 (MZ Automation libiec61850). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19110",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19110 (DataGear). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2411 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24486 (Kludex python-multipart). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47685",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47685 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47687",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47687 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47688",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47688 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47689",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47689 (fogproject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5336",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5336 (Unknown DataPress (Dataverse Integration)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56816",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56816 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56821",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56821 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66041 (FFmpeg). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66758",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66759",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66759 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66838",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66838 (elixir-ecto postgrex). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67621",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67621 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67622",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67622 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70636",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70636 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-18577",
      "detail": "DUE DATE PASSED — CVE-2026-18577 (N-able N-central). CISA remediation deadline was August 6, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-2196",
      "detail": "RESCORED — CVE-2022-2196 (Linux Kernel). CVSS 5.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-46847",
      "detail": "RESCORED — CVE-2023-46847 (squid). CVSS 8.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-9675",
      "detail": "RESCORED — CVE-2024-9675 (buildah). CVSS 7.8 → 4.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23366",
      "detail": "RESCORED — CVE-2025-23366 (hal-console). CVSS 6.5 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-24486",
      "detail": "RESCORED — CVE-2026-24486 (Kludex python-multipart). CVSS 8.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-43964",
      "detail": "RESCORED — CVE-2026-43964 (Postfix). CVSS 3.7 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49875",
      "detail": "RESCORED — CVE-2026-49875 (Apache Software Foundation Apache CXF). CVSS 6.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62836",
      "detail": "RESCORED — CVE-2026-62836 (Microsoft Azure SQL Managed Instance). CVSS 8.7 → 10 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2019-18184",
      "detail": "ENRICHED — CVE-2019-18184. Received CVSS 9.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
