{
  "day": "2026-08-08",
  "boundary": "UTC calendar day",
  "published_count": 62,
  "by_severity": {
    "CRITICAL": 27,
    "HIGH": 8,
    "MEDIUM": 16,
    "LOW": 10
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-71954",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0213,
      "epss_percentile": 0.80478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71954"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-71955",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0213,
      "epss_percentile": 0.80479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formWsc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71955"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-71944",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71944"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-71945",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71945"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-71946",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71946"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-71947",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71947"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-71948",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71948"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-71949",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71949"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-71950",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formSmsManage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71950"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-71951",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71951"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-71952",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71952"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-71953",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via /boafrm/formNtp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71953"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-71956",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01738,
      "epss_percentile": 0.75869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-78",
      "title": "D-Link DWR-M961 Command Injection via app.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71956"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-71983",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01621,
      "epss_percentile": 0.74152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via wps.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71983"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-19266",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01516,
      "epss_percentile": 0.72486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kirachon",
      "product": "context-engine",
      "cwe": "CWE-74",
      "title": "Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19266"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-71984",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via urlfilter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71984"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-71985",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71985"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-71986",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via dmz Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71986"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-71987",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via alg function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71987"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-71988",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via portFw function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71988"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-71989",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via porTrigger function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71989"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-71990",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71990"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-71991",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71991"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-71992",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via macfilter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71992"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-19263",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01336,
      "epss_percentile": 0.68949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "INQUIRELAB",
      "product": "mcp-bridge-api",
      "cwe": "CWE-74",
      "title": "INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19263"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-19268",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.62116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "abdullah1854",
      "product": "MCPGateway",
      "cwe": "CWE-74",
      "title": "abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19268"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-19279",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00731,
      "epss_percentile": 0.51459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MIMICLab",
      "product": "mcp-pdf-vision",
      "cwe": "CWE-74",
      "title": "MIMICLab mcp-pdf-vision index.ts load_pdf command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19279"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-19281",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00624,
      "epss_percentile": 0.47224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adolfosalasgomez3011",
      "product": "slidev-builder-mcp",
      "cwe": "CWE-74",
      "title": "adolfosalasgomez3011 slidev-builder-mcp generateAssets Tool generateAssets.ts generateChart command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19281"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-19284",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MauricioMilano",
      "product": "coder-api",
      "cwe": "CWE-74",
      "title": "MauricioMilano coder-api Projects Endpoint projects.ts createProject command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19284"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-19282",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00614,
      "epss_percentile": 0.46725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andreahaku",
      "product": "llm_memory_mcp",
      "cwe": "CWE-74",
      "title": "andreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19282"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-14526",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00612,
      "epss_percentile": 0.46616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wupsales",
      "product": "AI Copilot – Content Generator",
      "cwe": "CWE-269",
      "title": "AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14526"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-71957",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00594,
      "epss_percentile": 0.45811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-120",
      "title": "D-Link DWR-M961 Buffer Overflow via app.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71957"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-71958",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00562,
      "epss_percentile": 0.44297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-M961",
      "cwe": "CWE-120",
      "title": "D-Link DWR-M961 Buffer Overflow via quicksetup.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71958"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-67620",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00426,
      "epss_percentile": 0.35736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-918",
      "title": "Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67620"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-8798",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-FJA",
      "cwe": "CWE-835",
      "title": "Native entropy source retries the CPU entropy instructions without limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8798"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-68082",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.23495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: fix two unsafe bare decodes in decode_lockers()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68082"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-16578",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection",
      "cwe": "CWE-200",
      "title": "Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16578"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-16267",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletters",
      "cwe": "CWE-502",
      "title": "Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16267"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-18988",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shapedplugin",
      "product": "Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ",
      "cwe": "CWE-79",
      "title": "Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18988"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-13505",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-FJA",
      "cwe": "CWE-772",
      "title": "Zeroisation of sensitive key material on garbage collection relies on finalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13505"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-16594",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-200",
      "title": "WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16594"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-16559",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YMC Filter",
      "cwe": "CWE-79",
      "title": "YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16559"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-16955",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Engine",
      "cwe": "CWE-22",
      "title": "AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16955"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-16269",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletters",
      "cwe": "CWE-287",
      "title": "Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16269"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-16562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Statistics",
      "cwe": "CWE-200",
      "title": "WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16562"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-16590",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-200",
      "title": "WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16590"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-16595",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-200",
      "title": "WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16595"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-16589",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16589"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-16948",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Solace Extra",
      "cwe": "CWE-284",
      "title": "Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16948"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-42170",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-131",
      "title": "Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42170"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-16282",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Appointment Hour Booking",
      "cwe": "CWE-287",
      "title": "Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16282"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-16608",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Download Monitor",
      "cwe": "CWE-862",
      "title": "Download Monitor < 5.2.6 - Unauthenticated Download Log Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16608"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-16953",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Engine",
      "cwe": "CWE-639",
      "title": "AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16953"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-16535",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Link Library",
      "cwe": "CWE-79",
      "title": "Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16535"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-68081",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68081"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-16574",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution",
      "cwe": "CWE-639",
      "title": "Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16574"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-19287",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "abrinsmead",
      "product": "mindpilot-mcp",
      "cwe": "CWE-22",
      "title": "abrinsmead mindpilot-mcp HistoryService path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19287"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-19270",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hulupeep",
      "product": "mcp-ui-probe",
      "cwe": "CWE-22",
      "title": "Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19270"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-19285",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaronsb",
      "product": "memory-graph",
      "cwe": "CWE-22",
      "title": "aaronsb memory-graph memoryTools.ts JsonMemoryStorage.saveMemories path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19285"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-19288",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "astralisone",
      "product": "rive-mcp-server-core",
      "cwe": "CWE-22",
      "title": "astralisone rive-mcp-server-core importRiveFile Flow importRiveFile.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19288"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-16558",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YMC Filter",
      "cwe": "CWE-79",
      "title": "YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16558"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-19259",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.0255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "libiec61850",
      "cwe": "CWE-119",
      "title": "MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19259"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19192",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19192 (DeepCool DisplayService). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19193",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19193 (Jiangmin Antivirus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19195",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19195 (V-Secure Jingyun Antivirus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19207",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19207 (PHPGurukul Company Visitor Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19212",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19212 (WonderTrader). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-18556",
      "detail": "DUE DATE PASSED — CVE-2026-18556 (N-able N-central). CISA remediation deadline was August 7, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-34486",
      "detail": "DUE DATE PASSED — CVE-2026-34486 (Apache Software Foundation Apache Tomcat). CISA remediation deadline was August 7, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-9198",
      "detail": "DUE DATE PASSED — CVE-2026-9198 (IBM Langflow OSS). CISA remediation deadline was August 7, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
