{
  "day": "2026-08-10",
  "boundary": "UTC calendar day",
  "published_count": 670,
  "by_severity": {
    "CRITICAL": 84,
    "HIGH": 252,
    "MEDIUM": 129,
    "LOW": 17
  },
  "kev_count": 0,
  "exploit_reference_count": 6,
  "awaiting_enrichment_count": 188,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-28672",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02631,
      "epss_percentile": 0.84312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-77",
      "title": "Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28672"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-71966",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.02078,
      "epss_percentile": 0.79974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-78",
      "title": "CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71966"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-19379",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01657,
      "epss_percentile": 0.74705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EFM",
      "product": "ipTIME AX8004M",
      "cwe": "CWE-77",
      "title": "EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19379"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-72590",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01281,
      "epss_percentile": 0.67743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alseambusher",
      "product": "crontab-ui",
      "cwe": "CWE-93",
      "title": "alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72590"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-13206",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01269,
      "epss_percentile": 0.67474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel Networks",
      "product": "WAH7601",
      "cwe": "CWE-78",
      "title": "Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13206"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-72589",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01221,
      "epss_percentile": 0.66289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alseambusher",
      "product": "crontab-ui",
      "cwe": "CWE-78",
      "title": "alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72589"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-42537",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01202,
      "epss_percentile": 0.65758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-94",
      "title": "Apache Ranger: Remote Code Execution via JDBC URL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42537"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-44416",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01158,
      "epss_percentile": 0.6456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-94",
      "title": "Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44416"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-55799",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01134,
      "epss_percentile": 0.63917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-94",
      "title": "Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55799"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-72580",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00931,
      "epss_percentile": 0.57846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duhow",
      "product": "xiaoai-patch",
      "cwe": "CWE-78",
      "title": "duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72580"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-72573",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00905,
      "epss_percentile": 0.57055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "4xmen",
      "product": "pm2panel",
      "cwe": "CWE-78",
      "title": "4xmen pm2panel - Authenticated OS Command Injection via id Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72573"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-72577",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00855,
      "epss_percentile": 0.55515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "fprime-gds",
      "cwe": "CWE-306",
      "title": "NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72577"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-72572",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0077,
      "epss_percentile": 0.52781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "o1lab",
      "product": "xmysql",
      "cwe": "CWE-22",
      "title": "o1lab xmysql - Unauthenticated Path Traversal via name Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72572"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-72571",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00767,
      "epss_percentile": 0.52711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mustafaakin",
      "product": "cast-localvideo",
      "cwe": "CWE-22",
      "title": "mustafaakin cast-localvideo - Unauthenticated Path Traversal via dir Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72571"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-40920",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00732,
      "epss_percentile": 0.5149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-269",
      "title": "Apache Ranger: Privilege Escalation via URL Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40920"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-18948",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0069,
      "epss_percentile": 0.5,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-502",
      "title": "Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18948"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-68160",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00677,
      "epss_percentile": 0.49469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68160"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-72579",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00645,
      "epss_percentile": 0.48155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "HyperCP",
      "cwe": "CWE-78",
      "title": "NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72579"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-73033",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00644,
      "epss_percentile": 0.48097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sucuri",
      "product": "sucuri-wordpress-plugin",
      "cwe": "CWE-22",
      "title": "Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73033"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-32227",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0064,
      "epss_percentile": 0.47897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-89",
      "title": "Apache Ranger: SQL Injection vulnerability in lookup functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32227"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-72901",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00634,
      "epss_percentile": 0.47659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Remote Code Execution via volume-backup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72901"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-55814",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00629,
      "epss_percentile": 0.47427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-306",
      "title": "Apache Ranger: Download APIs expose plugin data without authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55814"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-68154",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00626,
      "epss_percentile": 0.4731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: reject zero bucket types in crush_decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68154"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-68158",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00626,
      "epss_percentile": 0.4731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: Fix multiplication overflow in decode_new_up_state_weight()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68158"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-68161",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00626,
      "epss_percentile": 0.4731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: close UDP tunnel sockets during netns teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68161"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-65945",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0061,
      "epss_percentile": 0.46521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-532",
      "title": "Apache Ranger: Logs contain replayable JWT bearer tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65945"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-68379",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00609,
      "epss_percentile": 0.465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: fix TIME_WAIT socket reference leak on PSP policy failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68379"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-68156",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00608,
      "epss_percentile": 0.46459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: refresh auth->authorizer_buf{,_len} after authorizer update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68156"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-68155",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00603,
      "epss_percentile": 0.46223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: Reject monmaps advertising zero monitors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68155"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-68157",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00603,
      "epss_percentile": 0.46223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: guard missing CRUSH type name lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68157"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-66915",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.006,
      "epss_percentile": 0.46073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fabrikar.com",
      "product": "Fabrik extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.9",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66915"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-72735",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00598,
      "epss_percentile": 0.45978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-77",
      "title": "Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72735"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-61899",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00595,
      "epss_percentile": 0.45859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tapestry",
      "cwe": "CWE-200",
      "title": "Apache Tapestry: Possible classpath file download through URL manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61899"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-65948",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00592,
      "epss_percentile": 0.45714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-307",
      "title": "Apache Ranger: UnixAuth lacks brute-force protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65948"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-18941",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-306",
      "title": "Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18941"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-72885",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00577,
      "epss_percentile": 0.45014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72885"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-10754",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00574,
      "epss_percentile": 0.44863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pegasystems",
      "product": "Pega Infinity",
      "cwe": "CWE-347",
      "title": "Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10754"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-18951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00572,
      "epss_percentile": 0.44776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 3.3",
      "cwe": "CWE-284",
      "title": "Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainjobs crud into standard edit clusterrole",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18951"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-72899",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00566,
      "epss_percentile": 0.44484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metabase",
      "product": "Metabase",
      "cwe": "CWE-89",
      "title": "Metabase SQL injection via public card or dashboard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72899"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-68341",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00565,
      "epss_percentile": 0.44437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: fix use after free in unlock_ovpn()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68341"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-44630",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00565,
      "epss_percentile": 0.44436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-400",
      "title": "Apache IoTDB: RPC service denial of service via unchecked Thrift string length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44630"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-65942",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00564,
      "epss_percentile": 0.44409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ranger",
      "cwe": "CWE-297",
      "title": "Apache Ranger: Clients accept TLS certificates issued for other hostnames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65942"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-68159",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00553,
      "epss_percentile": 0.43818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68159"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-69118",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cachethq",
      "product": "cachet",
      "cwe": "CWE-863",
      "title": "Cachet 2.4.1 Authenticated Server-Side Template Injection RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69118"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-72567",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00551,
      "epss_percentile": 0.43696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncFuncAI",
      "product": "deepwiki-open",
      "cwe": "CWE-22",
      "title": "deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72567"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-72902",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00539,
      "epss_percentile": 0.43068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72902"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-72875",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72875"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-18618",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-770",
      "title": "Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable on listener",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18618"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-72592",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00535,
      "epss_percentile": 0.42861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dulldusk",
      "product": "phpfm",
      "cwe": "CWE-434",
      "title": "dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72592"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-68300",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00531,
      "epss_percentile": 0.42597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: auth: verify auth requirement when auth_chunk is NULL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68300"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-72593",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00527,
      "epss_percentile": 0.42413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dulldusk",
      "product": "phpfm",
      "cwe": "CWE-306",
      "title": "dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72593"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-72738",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.4208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72738"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-72740",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.4208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72740"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-68170",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00516,
      "epss_percentile": 0.41739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: fix stale skb->sk reference on subflow close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68170"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-72569",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cube-root",
      "product": "directory-serve",
      "cwe": "CWE-22",
      "title": "cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72569"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2025-15683",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TBEA",
      "product": "TBEA TLogger (TBEA Communication Box 3rd Generation)",
      "cwe": "CWE-121",
      "title": "Multiple Unauthenticated Denial-of-Service Conditions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15683"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-66405",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-489",
      "title": "DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66405"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-72688",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "opensignserver",
      "cwe": "CWE-306",
      "title": "OpenSignLabs opensignserver - Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72688"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-68123",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00497,
      "epss_percentile": 0.40595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "openvswitch: fix GSO userspace truncation underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68123"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-68136",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00497,
      "epss_percentile": 0.40594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: gro: fix double aggregation of flush-marked skbs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68136"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-68385",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00497,
      "epss_percentile": 0.40594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/checksum: Fix csum_partial() without vector facility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68385"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-18982",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00495,
      "epss_percentile": 0.40456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-250",
      "title": "Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterroles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18982"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2025-30241",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "HB810(US2) V1.0/1.6/2.0/2.6",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30241"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-72867",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0049,
      "epss_percentile": 0.40178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-20",
      "title": "Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72867"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-48159",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00488,
      "epss_percentile": 0.40095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dai-shi",
      "product": "use-reducer-async",
      "cwe": "CWE-506",
      "title": "use-reducer-async was vulnerable to malicious code execution via compromised commits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48159"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-68287",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drop_monitor: fix size calculations for 64-bit attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68287"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-68343",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00484,
      "epss_percentile": 0.39759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: validate DFS referral PathConsumed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68343"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-72733",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72733"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-68127",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ila: reload IPv6 header after pskb_may_pull in checksum adjust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68127"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-68137",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/x25: fix use-after-free in x25_kill_by_neigh()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68137"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-68144",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phonet: pep: fix use-after-free in pep_get_sb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68144"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2025-15681",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TBEA",
      "product": "TBEA TLogger (TBEA Communication Box 3rd Generation)",
      "cwe": "CWE-306",
      "title": "Insufficient Webserver Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15681"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-68096",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.39212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "audit: fix recursive locking deadlock in audit_dupe_exe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68096"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-72881",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00474,
      "epss_percentile": 0.39193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via database credentials in backup/restore commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72881"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-68117",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: clear sock->sk on the failed-insert path in tipc_sk_create()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68117"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-72876",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00469,
      "epss_percentile": 0.38822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72876"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-72565",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00469,
      "epss_percentile": 0.38777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tencent",
      "product": "APIJSON",
      "cwe": "CWE-89",
      "title": "Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72565"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-68129",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gve: fix Rx queue stall on alloc failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68129"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-68131",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rbd: Reset positive result codes to zero in object map update path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68131"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-68141",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68141"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-68381",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00463,
      "epss_percentile": 0.38441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: pin conn during async oplock break notification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68381"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-68388",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00463,
      "epss_percentile": 0.38441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: handle overlapping allocated ranges in fallocate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68388"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-19089",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Input Fields for WooCommerce",
      "cwe": "CWE-434",
      "title": "Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19089"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-72914",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-405",
      "title": "Mastodon: Exhausting data by an unauthenticated request to the admin retention API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72914"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-14450",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00452,
      "epss_percentile": 0.37735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 3.4",
      "cwe": "CWE-290",
      "title": "Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14450"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-68302",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.37584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "amt: re-read skb header pointers after every pull",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68302"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-18617",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-915",
      "title": "Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams enables local infile file exfiltration from operator pod",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18617"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-71962",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-862",
      "title": "Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71962"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-68083",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00446,
      "epss_percentile": 0.37296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix path resolution in ksmbd_vfs_kern_path_create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68083"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-68120",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rtase: Workaround for TX hang caused by hardware packet parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68120"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-68299",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68299"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-68315",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: validate stream count in sctp_process_strreset_inreq()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68315"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-72739",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00445,
      "epss_percentile": 0.37174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via Compose Shell Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72739"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-18608",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-250",
      "title": "Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.org */*, and clusterrole/binding crud cluster-wide",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18608"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-72736",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00433,
      "epss_percentile": 0.36286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-77",
      "title": "Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72736"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-72862",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00433,
      "epss_percentile": 0.36286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72862"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-66403",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.3616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-489",
      "title": "DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66403"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-18947",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-862",
      "title": "Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized full re-materialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18947"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-72721",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-178",
      "title": "Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72721"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-72884",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via Compose Custom Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72884"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-68376",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: fix auth_hmacs array size in struct sctp_cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68376"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-48161",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dai-shi",
      "product": "react18-use",
      "cwe": "CWE-506",
      "title": "react18-use was vulnerable to malicious code execution via compromised commits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48161"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-19404",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00416,
      "epss_percentile": 0.34848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-862",
      "title": "389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort cleanallruv replication maintenance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19404"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-18949",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-250",
      "title": "Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18949"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-68097",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: validate ACE size against SID sub-authorities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68097"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-68098",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: bound DACL dedup walk to copied ACEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68098"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-72719",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.34346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chatwoot",
      "product": "chatwoot",
      "cwe": "CWE-915",
      "title": "Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72719"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-16985",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00406,
      "epss_percentile": 0.33977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Squeeze",
      "cwe": "CWE-434",
      "title": "Squeeze < 1.7.12 - Author+ Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16985"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-68196",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: wilc1000: validate assoc response length before subtracting header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68196"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-68352",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath6kl: fix OOB read from firmware IE lengths in connect event",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68352"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-68100",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68100"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-72877",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via dockerImage in buildRemoteDocker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72877"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2025-13294",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.33513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TBEA",
      "product": "TBEA TLogger (TBEA Communication Box 3rd Generation)",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13294"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-72883",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-862",
      "title": "Dokploy: WebSocket Terminal Missing Service-Level Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72883"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-66738",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.004,
      "epss_percentile": 0.33387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPIP",
      "product": "SPIP",
      "cwe": "CWE-94",
      "title": "SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66738"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-64940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nishishi Factory",
      "product": "Tegalog -Fumy Otegaru Memo Logger-",
      "cwe": "CWE-625",
      "title": "Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64940"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-68192",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmfmac: make release_scratchbuffers idempotent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68192"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-68199",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath6kl: fix OOB access from firmware ADDBA window size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68199"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-13170",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-22",
      "title": "Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13170"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-48158",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dai-shi",
      "product": "use-context-selector",
      "cwe": "CWE-506",
      "title": "use-context-selector was vulnerable to malicious code execution via compromised commits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48158"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-48160",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dai-shi",
      "product": "react-tracked",
      "cwe": "CWE-506",
      "title": "react-tracked was vulnerable to malicious code execution via compromised commits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48160"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2025-15682",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TBEA",
      "product": "TBEA TLogger (TBEA Communication Box 3rd Generation)",
      "cwe": "CWE-770",
      "title": "Unauthenticated Resource Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15682"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-18611",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-338",
      "title": "Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand) for db and s3 credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18611"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-72691",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "opensignserver",
      "cwe": "CWE-288",
      "title": "OpenSignLabs opensignserver - Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72691"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-66411",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-303",
      "title": "DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66411"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-71392",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Emacs",
      "cwe": "CWE-190",
      "title": "Integer Overflow in GNU Emacs for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71392"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-71393",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Emacs",
      "cwe": "CWE-190",
      "title": "Heap Buffer Overflow in GNU Emacs for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71393"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-72723",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00385,
      "epss_percentile": 0.31793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72723"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-68118",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: challenge ACK for non-exact RST in SYN-RECEIVED",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68118"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-72911",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-1336",
      "title": "ERPNext: Possibility of server-side template injection due to missing validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72911"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-15467",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-266",
      "title": "Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15467"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-72575",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daptin",
      "product": "daptin",
      "cwe": "CWE-284",
      "title": "daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72575"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-73030",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frostming",
      "product": "unearth",
      "cwe": "CWE-22",
      "title": "unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73030"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-68283",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix use-after-free freeing trigger private data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68283"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-68119",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: initialize standalone TCP-AO response padding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68119"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-72872",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.3046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72872"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2025-13293",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00371,
      "epss_percentile": 0.30401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TBEA",
      "product": "TBEA TLogger (TBEA Communication Box 3rd Generation)",
      "cwe": "CWE-798",
      "title": "Backdoor / default root credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13293"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-72586",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-306",
      "title": "frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72586"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-68426",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.2991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: fix stale skb->prev after async crypto steals a GSO segment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68426"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-72868",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72868"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-72581",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duhow",
      "product": "xiaoai-patch",
      "cwe": "CWE-918",
      "title": "duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72581"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-72761",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.29456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vulnerability-lookup",
      "product": "vulnerability-lookup",
      "cwe": "CWE-918",
      "title": "Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo pass is_global check) in vulnerability-lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72761"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-72886",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00361,
      "epss_percentile": 0.29334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-269",
      "title": "Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72886"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-18950",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-269",
      "title": "Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref in rolebinding creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18950"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-48048",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xwiki",
      "product": "xwiki-platform",
      "cwe": "CWE-359",
      "title": "XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48048"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-21075",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "My Galaxy",
      "cwe": "CWE-939",
      "title": "Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21075"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-72916",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-918",
      "title": "Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72916"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-72882",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72882"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-13717",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 3.4",
      "cwe": "CWE-284",
      "title": "Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namespaces.from: all allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13717"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-72874",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via Unescaped Git URL in Clone Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72874"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-72865",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: OS Command Injection via compose `composePath`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72865"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-72869",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-77",
      "title": "Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72869"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-18412",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.28145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenCart",
      "product": "OpenCart",
      "cwe": null,
      "title": "The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18412"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-18621",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-266",
      "title": "Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18621"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-72582",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastschema",
      "product": "fastschema",
      "cwe": "CWE-476",
      "title": "fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72582"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-71965",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-345",
      "title": "CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71965"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-68124",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mctp: serial: handle zero-length frames to prevent rx buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68124"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-16298",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00341,
      "epss_percentile": 0.27288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FoodBoxBooker",
      "cwe": "CWE-269",
      "title": "FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16298"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-16299",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00341,
      "epss_percentile": 0.27288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Single Sign On For TNG",
      "cwe": "CWE-287",
      "title": "Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16299"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-13600",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AutoNetTV Relay",
      "cwe": "CWE-287",
      "title": "AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13600"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-70622",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "composefs",
      "product": "tar-rs",
      "cwe": "CWE-59",
      "title": "tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70622"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-64941",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00341,
      "epss_percentile": 0.27181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoenixframework",
      "product": "phoenix_live_view",
      "cwe": "CWE-601",
      "title": "Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64941"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-47754",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NCEAS",
      "product": "metacat",
      "cwe": "CWE-22",
      "title": "unauthenticated path traversal in Metacat 2.x",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47754"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-72726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Unauthorized eavesdropping on private AI bot conversations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72726"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-72873",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-200",
      "title": "Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged service readers via `application.one`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72873"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-16626",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.2601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jaspersoft",
      "product": "JasperReports Server",
      "cwe": "CWE-611",
      "title": "JasperReports Server: XXE Injection Vulnerability (Unauthenticated)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16626"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-66407",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-327",
      "title": "DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66407"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-11810",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11810"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-68871",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Yandex provider",
      "cwe": "CWE-639",
      "title": "Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68871"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-68872",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Amazon provider",
      "cwe": "CWE-639",
      "title": "Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68872"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-71391",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Emacs",
      "cwe": "CWE-193",
      "title": "Off-by-One Error in GNU Emacs for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71391"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-66409",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-1391",
      "title": "DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66409"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-72689",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "opensignserver",
      "cwe": "CWE-639",
      "title": "OpenSignLabs opensignserver - Broken Object Level Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72689"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-72722",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72722"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-72724",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-639",
      "title": "Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72724"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-18620",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.2495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-639",
      "title": "Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authorization check — confused deputy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18620"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-71964",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-59",
      "title": "CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71964"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-14206",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "HT Contact Form",
      "cwe": "CWE-200",
      "title": "HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14206"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-17541",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "File Manager",
      "cwe": "CWE-200",
      "title": "Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17541"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-18470",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Login & Register Forms",
      "cwe": "CWE-200",
      "title": "Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18470"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-57279",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cybozu, Inc",
      "product": "Cybozu Garoon",
      "cwe": "CWE-79",
      "title": "Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57279"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-72564",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.2419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fosrl",
      "product": "Pangolin",
      "cwe": "CWE-639",
      "title": "fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72564"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-72903",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "tabby",
      "cwe": "CWE-22",
      "title": "Tabby: Windows SFTP path traversal allows a malicious server to write files outside the selected download directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72903"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-68125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mac802154: llsec: reject frames shorter than the authentication tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68125"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-12339",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR6400 v5.3",
      "cwe": "CWE-22",
      "title": "Authenticated Arbitrary File Write Vulnerability in multiple devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12339"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-16456",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-441",
      "title": "Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account crd confused deputy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16456"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-72866",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-862",
      "title": "WebSocket Terminal Auth Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72866"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-59090",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-191",
      "title": "Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59090"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-18942",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-94",
      "title": "Feast-operator: feast: feast apply cronjob runs user python with feature-server sa — tenant code to sa token escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18942"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-17542",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "File Manager",
      "cwe": "CWE-200",
      "title": "Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17542"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-19049",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProSolution WP Client",
      "cwe": "CWE-89",
      "title": "ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19049"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-72900",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metabase",
      "product": "Metabase",
      "cwe": "CWE-862",
      "title": "Metabase information exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72900"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-72720",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72720"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-72863",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-269",
      "title": "Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72863"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-72880",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72880"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-72734",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-639",
      "title": "Dokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72734"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-72871",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-306",
      "title": "Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72871"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-63106",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Razinsoft",
      "product": "Ready eCommerce",
      "cwe": "CWE-89",
      "title": "ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63106"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-17540",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "File Manager",
      "cwe": "CWE-284",
      "title": "Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17540"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-21061",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21061"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-71959",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitwarden",
      "product": "server",
      "cwe": "CWE-862",
      "title": "Bitwarden Server < 2026.7.2 Audit Log Injection via POST /collect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71959"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-72904",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.21355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "firecrawl",
      "product": "firecrawl",
      "cwe": "CWE-77",
      "title": "Firecrawl: Arbitrary file read via JSON Schema $ref expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72904"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-18786",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CheckView",
      "cwe": "CWE-287",
      "title": "CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18786"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-72908",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-89",
      "title": "ERPNext: Possibility of SQL injection due to missing validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72908"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-72759",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "cti-transmute",
      "cwe": "CWE-862",
      "title": "cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data Disclosure After Conversion Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72759"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-18478",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magnolia DXP",
      "product": "Magnolia CMS",
      "cwe": "CWE-79",
      "title": "Stored XSS in Magnolia CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18478"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-68353",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68353"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-18030",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BricksForge",
      "cwe": "CWE-862",
      "title": "Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18030"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-18468",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Login & Register Forms",
      "cwe": "CWE-287",
      "title": "Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18468"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-18469",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Login & Register Forms",
      "cwe": "CWE-287",
      "title": "Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18469"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-71394",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Emacs",
      "cwe": "CWE-1284",
      "title": "Heap Use of Uninitialized Memory in GNU Emacs for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71394"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-72879",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00278,
      "epss_percentile": 0.20324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via Registry Credentials in Swarm Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72879"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-72870",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via Docker Credentials in buildRemoteDocker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72870"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-72729",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00278,
      "epss_percentile": 0.20323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Stored XSS in discourse-local-dates plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72729"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-72915",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-200",
      "title": "Mastodon: Personally-identifying information disclosure due to incorrect access control validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72915"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-69114",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spacebar Server",
      "product": "Spacebar Server",
      "cwe": "CWE-639",
      "title": "Spacebar Server Cross-Channel Message Deletion via Permission Check Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69114"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-14293",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Autopay",
      "cwe": "CWE-79",
      "title": "Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14293"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-68354",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firewire: net: Fix fragmented datagram reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68354"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-72910",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-862",
      "title": "ERPNext: Unauthorised modification of master data due to missing validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72910"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-72864",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-862",
      "title": "Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72864"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-11809",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11809"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-72692",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "opensignserver",
      "cwe": "CWE-862",
      "title": "OpenSignLabs opensignserver - Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72692"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-72591",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gabehf",
      "product": "Koito",
      "cwe": "CWE-918",
      "title": "Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72591"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-72909",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-284",
      "title": "ERPNext: Broken Access Control on certain endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72909"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-68140",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/iucv: fix use-after-free of a severed iucv_path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68140"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-68198",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath6kl: fix use-after-free in aggr_reset_state()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68198"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-68373",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68373"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-72917",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mintplex-Labs",
      "product": "anything-llm",
      "cwe": "CWE-180",
      "title": "AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72917"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-72751",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "cti-transmute",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious STIX/MISP Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72751"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-72878",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00267,
      "epss_percentile": 0.18973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72878"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-68091",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: wacom: stop hardware after post-start probe failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68091"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-19384",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Doctors Appointment System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19384"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-19389",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19389"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-68402",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.1784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: bound element ID read when checking non-inheritance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68402"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-72566",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "automatisch",
      "product": "automatisch",
      "cwe": "CWE-918",
      "title": "automatisch - Server-Side Request Forgery via HTTP Request Custom Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72566"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-68326",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mwifiex: bound uAP association event IEs to the event buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68326"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-68389",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_qca: Clear memdump state on invalid dump size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68389"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-68397",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/iucv: take a reference on the socket found in afiucv_hs_rcv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68397"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-14237",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "vitepos",
      "cwe": "CWE-269",
      "title": "Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14237"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-17022",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Salon Booking System",
      "cwe": "CWE-200",
      "title": "Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17022"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-18946",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.1742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Contact Form to Any API",
      "cwe": "CWE-200",
      "title": "Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18946"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-12984",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel Networks",
      "product": "WAH7601",
      "cwe": "CWE-522",
      "title": "Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12984"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-16257",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Arvow AI SEO Writer",
      "cwe": "CWE-287",
      "title": "Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16257"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-68425",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/mad: Drop unmatched RMPP responses before reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68425"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-72690",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Attendize",
      "product": "Attendize",
      "cwe": "CWE-639",
      "title": "Attendize Attendize - Cross-Tenant Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72690"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-19433",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19433"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-15581",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-306",
      "title": "Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-rbac-proxy, exposing unauthenticated quarkus api cluster-wide",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15581"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-11811",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00252,
      "epss_percentile": 0.1696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-772",
      "title": "Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11811"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-68085",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.1681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68085"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-72588",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bluewave-labs",
      "product": "Checkmate",
      "cwe": "CWE-204",
      "title": "bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password Recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72588"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-72732",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Templates endpoint exposes hidden tag names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72732"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-72737",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00248,
      "epss_percentile": 0.16382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-639",
      "title": "Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72737"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-72584",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastschema",
      "product": "fastschema",
      "cwe": "CWE-367",
      "title": "fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72584"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-72907",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-285",
      "title": "ERPNext: Broken Access Control on certain endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72907"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-19387",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19387"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-69116",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xpf0000",
      "product": "FlyEnv",
      "cwe": "CWE-79",
      "title": "FlyEnv < 4.18.0 Cross-Site Scripting via v-html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69116"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-68393",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sync: extend conn_hash lookup critical sections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68393"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-68409",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: defer link RX stats percpu free to RCU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68409"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-19053",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProSolution WP Client",
      "cwe": "CWE-89",
      "title": "ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19053"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-72574",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picocms",
      "product": "Pico",
      "cwe": "CWE-644",
      "title": "picocms Pico - Host Header Injection Enables Script Source Hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72574"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-14886",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault Enterprise",
      "cwe": "CWE-862",
      "title": "Vault Enterprise vulnerable to cross-namespace entity deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14886"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-72760",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-200",
      "title": "cti-transmute Following List Exposes User Email Addresses to Authenticated Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72760"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-6426",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-681",
      "title": "Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6426"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-59233",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59233"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-72919",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-862",
      "title": "Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72919"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-72730",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72730"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-15047",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "s2Member",
      "cwe": "CWE-79",
      "title": "s2Member < 260805 - Contributor+ Stored XSS via Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15047"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-14860",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Podcast Player",
      "cwe": "CWE-918",
      "title": "Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14860"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-72727",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.1457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Stored XSS in the moderation review queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72727"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-19077",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Duplicate Post",
      "cwe": "CWE-639",
      "title": "Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19077"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-6374",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel Networks",
      "product": "WAH7601",
      "cwe": "CWE-798",
      "title": "Hardcoded Credentials in Zyxel WAH7601 Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6374"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-72731",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-89",
      "title": "Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explorer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72731"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-68414",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.1412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: cancel sched scan results work on unregister",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68414"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-44401",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Typemill",
      "product": "Typemill",
      "cwe": "CWE-79",
      "title": "Typemill CMS 2.x Persistent XSS via Markdown javascript URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44401"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-59087",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-787",
      "title": "Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59087"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-68278",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00226,
      "epss_percentile": 0.13537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/dp/mst: fix buffer overflows in sideband chunk accumulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68278"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-68870",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Microsoft Azure provider",
      "cwe": "CWE-639",
      "title": "Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68870"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-68359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00225,
      "epss_percentile": 0.1338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68359"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-68360",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00225,
      "epss_percentile": 0.1338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68360"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-17018",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.1308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CubeWP Framework",
      "cwe": "CWE-639",
      "title": "CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17018"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-15237",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MotoPress Hotel Booking",
      "cwe": "CWE-862",
      "title": "Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15237"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2025-30237",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "HB810(US2) V1.0/1.6/2.0/2.6",
      "cwe": "CWE-862",
      "title": "Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30237"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-68390",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68390"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-19383",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.1257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saithink",
      "product": "SaiAdmin",
      "cwe": "CWE-284",
      "title": "saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19383"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-72725",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Stored XSS in staff action logs injects staff UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72725"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-56620",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL BigFix Mobile",
      "cwe": "CWE-209",
      "title": "HCL BigFix Mobile is vulnerable to information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56620"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-17012",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Accept PayPal & Stripe with Subscriptions for WooCommerce",
      "cwe": "CWE-284",
      "title": "Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17012"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-73035",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raineorshine",
      "product": "npm-check-updates",
      "cwe": "CWE-150",
      "title": "npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73035"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-16949",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Term Pages",
      "cwe": "CWE-89",
      "title": "Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16949"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-19278",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Security 4",
      "cwe": "CWE-625",
      "title": "Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19278"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-68130",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: defer destroy_previous_session() until after NTLM authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68130"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-68164",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.1134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/damon/core: disallow overlapping input ranges for damon_set_regions()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68164"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-68187",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "exec: fix unsigned loop counter wrap in transfer_args_to_stack()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68187"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-68203",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: vivid: fix cleanup bugs in vivid_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68203"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-68205",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68205"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-68207",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: ti: vpe: unwind v4l2 device registration on probe error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68207"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-68212",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.1134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: saa7134: Fix a possible memory leak in saa7134_video_init1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68212"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-68214",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rtl2832: fix use-after-free in rtl2832_remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68214"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-68215",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: radio-si476x: Unregister v4l2_device on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68215"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-68217",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: pwc: Drain fill_buf on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68217"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-68218",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: pci: dm1105: Free allocated workqueue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68218"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-68220",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68220"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-68221",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: nuvoton: npcm-video: fix memory leaks in probe and remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68221"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-68223",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: meson: vdec: Fix memory leak in error path of vdec_open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68223"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-68225",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: i2c: alvium: fix critical pointer access in alvium_ctrl_init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68225"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-68226",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cx23885: add ioremap return check and cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68226"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-68227",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cx231xx: fix devres lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68227"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-68231",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: airspy: Return queued buffers on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68231"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-68251",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68251"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-68261",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/imagination: fix error checking of pvr_vm_context_lookup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68261"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-68277",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68277"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-68339",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btusb: validate Realtek vendor event length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68339"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-68346",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: hda: cs35l41: validate and free ACPI mute object",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68346"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-68351",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68351"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-68405",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.11341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68405"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-68422",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.1134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68422"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-6791",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-121",
      "title": "Potential stack-based buffer clash during tilde expansion in wordexp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6791"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-68268",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.11044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe: Return error on non-migratable faults requiring devmem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68268"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-68270",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.11044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/sysfb: Avoid possible truncation with calculating visible size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68270"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-66408",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-1391",
      "title": "The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66408"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-72906",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-862",
      "title": "ERPNext: Unauthorised triggering of automated emails due to missing validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72906"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-66404",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-295",
      "title": "DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66404"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-72918",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.1018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-862",
      "title": "Rocket.Chat: Insecure implementation of websocket notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72918"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-68165",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/damon/core: validate ranges in damon_set_regions()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68165"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-68169",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: pm: userspace: fix use-after-free in get_local_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68169"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-68175",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix resource leak on mmiotrace trace_pipe close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68175"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-68176",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68176"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-68180",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "intel_th: fix MSC output device reference leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68180"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-68181",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mei: bus: access mei_device under device_lock on cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68181"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-68182",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "comedi: comedi_parport: deal with premature interrupt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68182"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-68183",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: stratix10-svc: fix memory leaks and list corruption bugs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68183"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-68184",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cdrom: fix stack out-of-bounds read in CDROMVOLCTRL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68184"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-68185",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Move jump_label_init() before parse_early_param()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68185"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-68186",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "binfmt_misc: set have_execfd only once the interpreter is opened",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68186"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-68188",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.1019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: RFCOMM: Fix session UAF in set_termios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68188"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-68190",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68190"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-68193",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68193"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-68194",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68194"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-68195",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68195"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-68197",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68197"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-68250",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68250"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-68269",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/gem: Add missing nospec on parallel submit slot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68269"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-68296",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68296"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-68304",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmfmac: fix 802.1X-SHA256 call trace warning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68304"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-68313",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: fix infinite loop in __tipc_nl_compat_dumpit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68313"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-68321",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: txgbe: fix FDIR filter leak on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68321"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-68322",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68322"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-68344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.1019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68344"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-68368",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68368"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-68369",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: printer: fix infinite loop in printer_read()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68369"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-68378",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68378"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-68386",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, sockmap: Reject unhashed UDP sockets on sockmap update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68386"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-68395",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68395"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-68396",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.10181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: core: wake eh reliably when using scsi_schedule_eh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68396"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-68410",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.1019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: libertas: fix memory leak in helper_firmware_cb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68410"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-18666",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Library Management System",
      "cwe": "CWE-89",
      "title": "Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18666"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-68166",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "userfaultfd: prevent registration of special VMAs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68166"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-68168",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Fix afs_edit_dir_remove() to get, not find, block 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68168"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-68174",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Fix union collision of module and refcnt for dynamic events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68174"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-68208",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68208"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-68224",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: mali-c55: Fix possible ERR_PTR in enable_streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68224"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-68232",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68232"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-68235",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: dce100: skip non-DP stream encoders for DP MST",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68235"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-68241",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/mst: limit DP MST ESI service loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68241"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-68345",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm_mpam: guard MBWU state before adding it to garbage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68345"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-68412",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68412"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-12624",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault",
      "cwe": "CWE-863",
      "title": "Vault vulnerable to LIST authorization bypass via trailing-slash strip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12624"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-68276",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00193,
      "epss_percentile": 0.09391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx: fix cleaner shader IB buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68276"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-68349",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00193,
      "epss_percentile": 0.09391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: carl9170: fix buffer overflow in rx_stream failover path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68349"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-68421",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00192,
      "epss_percentile": 0.09257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68421"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-71577",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Global Hub",
      "cwe": "CWE-522",
      "title": "Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kubeconfigs to all managed hubs during migration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71577"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-68255",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/virtio: bound EDID block reads to the response buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68255"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-12971",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00189,
      "epss_percentile": 0.08847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": "CWE-918",
      "title": "LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12971"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-68167",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: do not try compression for data reloc inodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68167"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-68191",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath12k: fix NULL pointer dereference in rhash table destroy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68191"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-68242",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/gt: Fix NULL deref on sched_engine alloc failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68242"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-68286",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drop_monitor: perform u64_stats updates under IRQ-disabled section",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68286"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-68303",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vc4: hvs/v3d: Fix null dereference in unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68303"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-68312",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68312"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-68358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00188,
      "epss_percentile": 0.08825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68358"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-68361",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00188,
      "epss_percentile": 0.08824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68361"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-17016",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Accept PayPal & Stripe with Subscriptions for WooCommerce",
      "cwe": "CWE-284",
      "title": "Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17016"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-14238",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "vitepos",
      "cwe": "CWE-89",
      "title": "Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14238"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-68413",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00186,
      "epss_percentile": 0.08554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68413"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-72728",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-20",
      "title": "Discourse: Onebox iframe origin allowlist enforces URL authority boundary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72728"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-72587",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreBunch",
      "product": "Instatic",
      "cwe": "CWE-444",
      "title": "Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72587"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-72912",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gchq",
      "product": "CyberChef",
      "cwe": "CWE-400",
      "title": "CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72912"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-72578",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "FreePBX Framework",
      "cwe": "CWE-352",
      "title": "FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72578"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-68179",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "misc: nsm: only unlock nsm_dev on post-lock error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68179"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-68371",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: musb: omap2430: Do not put borrowed of_node in probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68371"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-15229",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Pinpoint Booking System",
      "cwe": "CWE-863",
      "title": "Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15229"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-17021",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Salon Booking System",
      "cwe": "CWE-862",
      "title": "Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17021"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-68093",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.07944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68093"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-18934",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RSS Aggregator by Feedzy",
      "cwe": "CWE-863",
      "title": "RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18934"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-68342",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: avoid putting unrelated P2P peer on socket release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68342"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-72522",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.0748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat project",
      "product": "libexpat",
      "cwe": "CWE-125",
      "title": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72522"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-68088",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: function: rndis: add length check to response query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68088"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-68090",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "debugobjects: Plug race against a concurrent OOM disable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68090"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-68202",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: seq: close a re-opened queue timer in the destructor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68202"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-68204",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: vivid: check for vb2_is_busy() when toggling caps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68204"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-68206",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-ctrls: validate HEVC active reference counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68206"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-68209",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: sun4i-csi: Return queued buffers on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68209"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-68210",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: stm32: dcmi: unregister notifier on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68210"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-68213",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rtl2832_sdr: Return queued buffers on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68213"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-68216",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: pwc: Return queued buffers on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68216"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-68219",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: nxp: imx8-isi: Fix potential out-of-bounds issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68219"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-68338",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/packet: avoid fanout hook re-registration after unregister",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68338"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-68126",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mac802154: hold an interface reference across the scan worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68126"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-68133",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ice: fix PTP Call Trace during PTP release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68133"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-68135",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: hip04: fix RX buffer leak on build_skb failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68135"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-68139",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5e: Use sender devcom for MPV master-up",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68139"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-68146",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ftrace: Add global mutex to serialize trace_parser access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68146"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-68151",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "binfmt_elf_fdpic: only honour the first PT_INTERP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68151"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-68252",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68252"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-68256",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68256"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-68271",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/nouveau: fix reversed error cleanup order in ucopy functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68271"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-68272",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68272"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-68279",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68279"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-68280",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68280"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-68281",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/imagination: Count paired job fence as dependency in prepare_job()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68281"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-68325",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Bound the early ACPI HID map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68325"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-68333",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dpaa2-switch: put MAC endpoint device on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68333"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-68336",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bonding: fix devconf_all NULL dereference when IPv6 is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68336"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-68350",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: carl9170: fix OOB read from off-by-two in TX status handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68350"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-68355",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68355"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-68363",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.0734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68363"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-68365",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: serial: io_edgeport: cap received transmit credits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68365"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-68366",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68366"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-68367",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_tcm: synchronize delayed set_alt with teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68367"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-68406",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: validate PMSR FTM preamble range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68406"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2025-30240",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "HB810(US2) V1.0/1.6/2.0/2.6",
      "cwe": "CWE-59",
      "title": "Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30240"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-68387",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "can: raw: add locking for raw flags bitfield",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68387"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-13701",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.0709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Advanced Excerpt",
      "cwe": "CWE-79",
      "title": "Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13701"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-68122",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: fix peer refcount leak in TCP error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68122"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-68132",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "super: fix emergency thaw deadlock on frozen block devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68132"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-68150",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/super: fix emergency thaw double-unlock of s_umount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68150"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-68211",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: stm32-dcmipp: Return queued buffers on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68211"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-68275",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68275"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-68282",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68282"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-68332",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: airoha: Fix potential use-after-free in airoha_ppe_deinit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68332"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-68334",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.07085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68334"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-68084",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.07003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: vme_user: fix location monitor leak in tsi148 bridge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68084"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-72743",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "SQLBot",
      "cwe": "CWE-79",
      "title": "SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72743"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-17023",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Salon Booking System",
      "cwe": "CWE-284",
      "title": "Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17023"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-68200",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: timer: don't re-enter an instance callback that is still running",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68200"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-68201",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: timer: drain a slave's callback before its master detaches it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68201"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-68230",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: amlogic-c3: Add validations for ae and awb config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68230"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-6373",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel Networks",
      "product": "WAH7601",
      "cwe": "CWE-497",
      "title": "Sensitive Data Exposure in Zyxel WAH7601 Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6373"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-14941",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-862",
      "title": "Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14941"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-15238",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MotoPress Hotel Booking",
      "cwe": "CWE-639",
      "title": "Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15238"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-68092",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "time/jiffies: Register jiffies clocksource before usage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68092"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-68099",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68099"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-68102",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: fix aperture mapping leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68102"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-68110",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68110"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-68111",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68111"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-68112",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68112"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-68113",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68113"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-68115",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68115"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-68234",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68234"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-68243",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68243"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-68244",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/gem: Do not leak siblings[] on proto context error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68244"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-68246",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68246"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-68247",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/bios: range check LFP Data Block panel_type2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68247"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-68248",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915: Return NULL on error in active_instance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68248"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-68249",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68249"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-68254",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/vrr: require valid min/max vfreq for VRR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68254"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-68259",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Check bounds in allocate_event_notification_slot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68259"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-68267",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68267"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-68301",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: hsr: fix memory leak on slave unregistration by removing synced VLANs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68301"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-68306",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68306"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-68307",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7925: fix crash in reset link replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68307"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-68308",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68308"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-68309",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68309"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-68310",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: guard HE capability lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68310"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-68311",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7925: guard link STA in decap offload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68311"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-68317",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pds_core: fix auxiliary device add/del races",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68317"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-68318",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pds_core: fix use-after-free on workqueue during remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68318"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-68319",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pds_core: fix deadlock between reset thread and remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68319"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-68324",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68324"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-68327",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wan: wanxl: Only reset hardware after BAR mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68327"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-68328",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfp: Check resource mutex allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68328"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-68331",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dpaa2-eth: put MAC endpoint device on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68331"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-68357",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68357"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-68362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68362"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-68372",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: core: port: Deattach Type-C connector on component unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68372"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-68403",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmfmac: initialize SDIO data work before cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68403"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-68407",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: nl80211: free RNR data on MBSSID mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68407"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-68408",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68408"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-68411",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211_hwsim: clamp virtio RX length before skb_put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68411"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-59091",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-787",
      "title": "Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59091"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-18960",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Block User Account",
      "cwe": "CWE-287",
      "title": "Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18960"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-68087",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68087"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-68089",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: core: fix uninitialized data in debugfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68089"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-68095",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse-uring: fix race between registration and connection abortion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68095"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-68233",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vc4: Shut down BO cache timer before teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68233"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-68238",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Release VFCT ACPI table reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68238"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-68239",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/ttm: Account for NULL and handle pages in ttm_pool_backup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68239"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-68292",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ice: prevent tstamp ring allocation for non-PF VSI types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68292"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-68356",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "watchdog: airoha: Prevent division by zero when clock frequency is zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68356"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-68163",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/page_vma_mapped: fix device-private PMD handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68163"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-72594",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobe-chat",
      "cwe": "CWE-79",
      "title": "lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72594"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-72576",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bludit",
      "product": "Bludit",
      "cwe": "CWE-79",
      "title": "Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72576"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-66410",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00165,
      "epss_percentile": 0.06182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "Android App \"ECOVACS PRO\"",
      "cwe": "CWE-295",
      "title": "Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66410"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-68162",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: avoid auth_enable sysctl UAF during netns teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68162"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-68294",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: qrtr: restrict socket creation to the initial network namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68294"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-68178",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "misc: nsm: pin the module while the device is open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68178"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-68228",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: chips-media: wave5: Move src_buf Removal to finish_encode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68228"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-68245",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68245"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-68260",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68260"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-17019",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17019"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-17010",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Saitama Addon Pack",
      "cwe": "CWE-79",
      "title": "Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17010"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-19075",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All-in-One Video Gallery",
      "cwe": "CWE-918",
      "title": "All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19075"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-17020",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Salon Booking System",
      "cwe": "CWE-639",
      "title": "Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17020"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-68285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: BPF: Fix memory leak in bpf_jit_free()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68285"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-68288",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.0594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68288"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-68289",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.0594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68289"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-68347",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Fix IRQ unsafe locking in gdom allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68347"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-68364",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Fix ISM dc_lock deadlock during suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68364"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-68375",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Handle partially initialized auxiliary devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68375"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-68240",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/gpusvm: publish dpagemap early to avoid device mapping leak on error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68240"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-68330",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: airoha: Fix DMA direction for NPU mailbox buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68330"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-59088",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-190",
      "title": "Gimp: gimp: denial of service via signed integer overflow in fli file processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59088"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-68329",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68329"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-68189",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sync: Protect UUID list traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68189"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-68229",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cedrus: skip invalid H.264 reference list entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68229"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-68172",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: make huge_ptep_get handled unaligned addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68172"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-68173",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: wait on ublk_dev_ready() instead of ub->completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68173"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-66484",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "cpio",
      "cwe": "CWE-22",
      "title": "Path Traversal in GNU cpio",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66484"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-68416",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: fix double free and WARN_ON in add_mtd_device() error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68416"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-68428",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86/mmu: Fix use-after-free on vendor module reload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68428"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-21060",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21060"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-21073",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.0519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21073"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-68094",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Preserve rq tracking across local DSQ dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68094"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-68105",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.0521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Fix kernel panic during driver load failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68105"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-68109",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68109"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-68114",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68114"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-68237",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/userq: fix indefinite fence wait during GPU reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68237"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-68291",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "idpf: fix max_vport related crash on allocation error during init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68291"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-68337",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject redirect helpers without a bpf_net_context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68337"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-68177",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Delay module ref count for \"enable_event\" trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68177"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-68295",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: BPF: Zero-extend signed ALU32 div/mod results",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68295"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-68404",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: use wiphy work for socket owner autodisconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68404"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2025-15680",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00154,
      "epss_percentile": 0.05128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TBEA",
      "product": "TBEA TLogger (TBEA Communication Box 3rd Generation)",
      "cwe": "CWE-497",
      "title": "Information Disclosure via UART",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15680"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-68418",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.05133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/irdma: Prevent user-triggered null deref on QP create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68418"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-21083",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Smart Switch",
      "cwe": "CWE-20",
      "title": "Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21083"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-18200",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FoodBoxBooker",
      "cwe": "CWE-639",
      "title": "FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18200"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-14211",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.0494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-639",
      "title": "Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14211"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-68274",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/guc: Fix buffer overflow in steered register list allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68274"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2025-32736",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ping Identity",
      "product": "PingFederate",
      "cwe": "CWE-352",
      "title": "PingFederate Administrative Console CSRF weaknesses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32736"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-66406",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00151,
      "epss_percentile": 0.04802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ECOVACS ROBOTICS",
      "product": "DEEBOT PRO M1",
      "cwe": "CWE-295",
      "title": "DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66406"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-68340",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: occ: validate poll response sensor blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68340"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-72583",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastschema",
      "product": "fastschema",
      "cwe": "CWE-79",
      "title": "fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72583"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-68086",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/khugepaged: write all dirty file folios when collapsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68086"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-69112",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "accelerate",
      "cwe": "CWE-22",
      "title": "Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69112"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-21063",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-926",
      "title": "Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21063"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-72913",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "kitty",
      "cwe": "CWE-77",
      "title": "Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72913"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-21070",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.0423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21070"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-68423",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.0425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68423"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-68424",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68424"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-68253",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/hdcp: check streams[] bounds before overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68253"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-68128",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ice: reject out-of-range ptype in ice_parser_profile_init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68128"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-68142",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "geneve: require CAP_NET_ADMIN in the device netns for changelink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68142"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-68121",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pppoe: reload header pointer after dev_hard_header()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68121"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-68143",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: slip: serialize receive against buffer reallocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68143"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-68145",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iomap: fix out-of-bounds bitmap_set() with zero-length range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68145"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-68222",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: msi2500: Return queued buffers on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68222"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-68257",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: fix 32-bit overflow in CWSR total size calculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68257"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-68264",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/pt: Reset current_op in xe_pt_update_ops_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68264"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-68370",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68370"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-68293",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5: Fix MCIA register buffer overflow on 32 dword reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68293"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-72570",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cube-root",
      "product": "directory-serve",
      "cwe": "CWE-79",
      "title": "cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72570"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-63105",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Razinsoft",
      "product": "Ready eCommerce",
      "cwe": "CWE-79",
      "title": "ReadyEcommerce < 4.5.2 Stored XSS via Chat and Support Ticket Systems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63105"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-21082",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Health",
      "cwe": "CWE-23",
      "title": "Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21082"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-66486",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "cpio",
      "cwe": "CWE-116",
      "title": "Improper Output Encoding in GNU cpio",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66486"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-68401",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68401"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-68108",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/vce: fix integer overflow in image size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68108"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2025-30238",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.0341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "HB810(US2) V1.0/1.6/2.0/2.6",
      "cwe": "CWE-863",
      "title": "Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30238"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2025-30239",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "HB810(US2) V1.0/1.6/2.0/2.6",
      "cwe": "CWE-321",
      "title": "Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30239"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-68149",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs: preserve ACL_DONT_CACHE state in forget_cached_acl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68149"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-71969",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-787",
      "title": "OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71969"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-68147",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fscrypt: Avoid dynamic allocation in fscrypt_get_devices()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68147"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-68152",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "amt: fix use-after-free in AMT delayed works",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68152"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-68266",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe: Hold a dma-buf reference for imported BOs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68266"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-68273",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Fix context pstate override handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68273"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-68284",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68284"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-68335",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rds: drop incoming messages that cross network namespace boundaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68335"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-68384",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68384"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-68415",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: clear mode callbacks after failed mode setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68415"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-72718",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaif-goose",
      "product": "goose",
      "cwe": "CWE-94",
      "title": "goose: Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72718"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-68380",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: Fix use-after-free of mm_struct in job scheduler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68380"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-56619",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL BigFix Mobile",
      "cwe": "CWE-79",
      "title": "HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56619"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-66485",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "cpio",
      "cwe": "CWE-789",
      "title": "Uncontrolled Memory Allocation in GNU cpio",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66485"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-68262",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/imagination: Fix user array stride in pvr_set_uobj_array()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68262"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-68348",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: tas2781: bound firmware description string parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68348"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-18370",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eradman",
      "product": "entr",
      "cwe": "CWE-122",
      "title": "Heap-based buffer overflow in entr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18370"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-63622",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-59",
      "title": "Libvirt: swtpm privilege escalation via symlink following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63622"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-68138",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: serialize qdisc_rtab_list against concurrent get/put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68138"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-68305",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68305"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-68382",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/guc: Hold device ref until queue teardown completes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68382"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-68383",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/guc: Keep scheduler timeline name alive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68383"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-68399",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix UAF in sock clone early bailouts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68399"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-68134",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ptp: ptp_s390: Add missing facility check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68134"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-68265",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68265"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-68258",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Check bounds on CRIU restore queue type and mqd size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68258"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-68107",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/vcn4: avoid rereading IB param length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68107"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-68104",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: invoke pm_genpd_remove() before freeing genpd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68104"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-68106",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: fix division by zero with invalid uvd dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68106"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-68297",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: fix u16 MTU truncation in media and bearer MTU validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68297"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-68314",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.0293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mctp i3c: clean up notifier and buses if driver register fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68314"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-68374",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.0293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: core: sysfs: add lock to bos_descriptors_read()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68374"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-68391",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68391"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-68392",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68392"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-68398",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68398"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-68419",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/irdma: Prevent rereg_mr for non-mem regions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68419"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-12570",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keras-team",
      "product": "keras-team/keras",
      "cwe": "CWE-770",
      "title": "Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12570"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-68298",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.0279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68298"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-68377",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: act_tunnel_key: Defer dst_release to RCU callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68377"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-68400",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68400"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-68320",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68320"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-21068",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21068"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-68153",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: remove debugfs files before client teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68153"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-68236",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: set new_stream to NULL after release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68236"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-68263",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/imagination: Fix double call to drm_sched_entity_fini()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68263"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-68290",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rds: tcp: unregister sysctl before tearing down listen socket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68290"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-68394",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68394"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-68427",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68427"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-71576",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Global Hub",
      "cwe": "CWE-345",
      "title": "Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source() for leaf-hub identity in all status handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71576"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-8718",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8718"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-68116",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: mdb: Fix source list corruption on a failed replace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68116"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-19074",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Advanced Classifieds & Directory Pro",
      "cwe": "CWE-200",
      "title": "Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19074"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-68316",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel: ethosu: Fix element size accounting for cmd stream validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68316"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-68323",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: serialize udp bearer replicast list updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68323"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-68417",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/siw: publish QP after initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68417"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-71967",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.0211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-476",
      "title": "OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71967"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-15059",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "systemd",
      "product": "systemd-oomd",
      "cwe": "CWE-22",
      "title": "systemd-oomd: unprivileged users can terminate arbitrary processes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15059"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-21067",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21067"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-21072",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21072"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-18503",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.02099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-1176",
      "title": "Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18503"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-19382",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.0205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Almico",
      "product": "Speedfan",
      "cwe": "CWE-401",
      "title": "Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19382"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-19380",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.02015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mullvad",
      "product": "wireguard.sys",
      "cwe": "CWE-664",
      "title": "Mullvad wireguard.sys IOCTL AdapterState reference count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19380"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-13133",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LY Corporation",
      "product": "LINE for Windows",
      "cwe": "CWE-427",
      "title": "A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13133"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-59112",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Estonian Information System Authority (RIA)",
      "product": "libdigidocpp",
      "cwe": "CWE-347",
      "title": "Signature validation vulnerability affecting DigiDoc applications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59112"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-68420",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: reject optional IPTFS templates in outbound policies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68420"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-21066",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.0166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21066"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-21065",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21065"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-19381",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kingston",
      "product": "FURY CTRL RGB Control Software",
      "cwe": "CWE-266",
      "title": "Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19381"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-21069",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-681",
      "title": "Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21069"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-21071",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21071"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-68103",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: reject mapping a reserved doorbell to a new queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68103"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-6368",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00107,
      "epss_percentile": 0.01299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glibc",
      "product": "glibc",
      "cwe": "CWE-908",
      "title": "wordexp with WRDE_APPEND can return or use invalid memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6368"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-21076",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Health",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21076"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-21077",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Health",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21077"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-21080",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Smart Switch",
      "cwe": "CWE-312",
      "title": "Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21080"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-21058",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-20",
      "title": "Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21058"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-21074",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Bixby",
      "cwe": "CWE-276",
      "title": "Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21074"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-71968",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-416",
      "title": "OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71968"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-66642",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Umbrella",
      "product": "WP Umbrella",
      "cwe": "CWE-352",
      "title": "WordPress WP Umbrella plugin 2.24.2-2.26.2 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66642"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-19411",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00098,
      "epss_percentile": 0.00867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7",
      "cwe": "CWE-476",
      "title": "Shim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns null",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19411"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-21078",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Smart Switch",
      "cwe": "CWE-345",
      "title": "Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21078"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-63623",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-732",
      "title": "Libvirt: information disclosure via world-readable storage volume images during clone/convert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63623"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-21062",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-939",
      "title": "Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21062"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-21064",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-284",
      "title": "Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21064"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-21059",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-926",
      "title": "Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21059"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-68148",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fscrypt: Add missing superblock check in find_or_insert_direct_key()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68148"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-21084",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "SmartThings",
      "cwe": "CWE-284",
      "title": "Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21084"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-21081",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "SamsungPassAutofill",
      "cwe": "CWE-926",
      "title": "Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21081"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-11812",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.0008,
      "epss_percentile": 0.00216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-362",
      "title": "UpdateHub: race condition on shared context causes out-of-bounds write and DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11812"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-15060",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00079,
      "epss_percentile": 0.00167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "systemd",
      "product": "systemd-machined",
      "cwe": "CWE-284",
      "title": "systemd-machined: unprivileged users can terminate arbitrary processes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15060"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-21079",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00065,
      "epss_percentile": 0.00019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Smart Switch",
      "cwe": "CWE-311",
      "title": "Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21079"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-16742",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00057,
      "epss_percentile": 0.00006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "systemd",
      "product": "systemd-homed",
      "cwe": "CWE-269",
      "title": "systemd-homed: local privilege escalation via missing home-record signature verification on the authenticate path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16742"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-34473",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-34473 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-34523",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-34523 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-34527",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-34527 (Microsoft Windows 10 Version 1507). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-36942",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-36942 (Microsoft Windows Server 2008 R2 Service Pack 1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-38647",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-38647 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-38648",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-38648 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-40444",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-40444 (Microsoft Windows 10 Version 1507). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-21338",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-21338 (Microsoft Windows 10 Version 1809). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-21413",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-21413 (Microsoft 365 Apps for Enterprise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-38217",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-38217 (Microsoft Windows 10 Version 1507). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10774 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10848",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10848 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15038",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15038 (Unknown InfiniteWP Client). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16032",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16032 (Unknown LWS Optimize). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16267",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16267 (Unknown Newsletters). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16269",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16269 (Unknown Newsletters). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16282",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16282 (Unknown Appointment Hour Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16548",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16548 (Unknown Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16559",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16559 (Unknown YMC Filter). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16574",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16574 (Unknown Dokan: AI Powered WooCommerce Multivendor Marketplace Solution). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16589",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16589 (Unknown WP Directory Kit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16608",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16608 (Unknown Download Monitor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16948",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16948 (Unknown Solace Extra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16953",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16953 (Unknown AI Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16955",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16955 (Unknown AI Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16957",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16957 (Unknown Slim SEO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16965",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16965 (Unknown Solace Extra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16988",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16988 (Unknown GeoDirectory). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16992",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16992 (Unknown Create). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17011",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17011 (Unknown Nexter Blocks). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17014 (Unknown WP Photo Album Plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17017",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17017 (Unknown CubeWP Framework). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17044 (Unknown Iptanus File Upload). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18032",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18032 (Unknown WP Data Access). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18037",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18037 (Unknown Create). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18357",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18357 (Unknown WPC Order Tip for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18464",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18464 (Unknown WP MAPS PRO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18465",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18465 (Unknown WP MAPS PRO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18473",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18473 (Unknown WP Directory Kit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18603",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18603 (Unknown PiWeb Cancel order / Refund request for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19243",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19243 (HKUDS nanobot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19341",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19341 (UTT HiPER 1200GW). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19342",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19342 (code-projects Task Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19343",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19343 (code-projects Task Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19344",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19344 (code-projects Task Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19346",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19346 (Tenda CH22). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19347",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19347 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19348",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19348 (Shenzhen Aitemi M300 Wi-Fi Repeater). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19352",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19352 (mifi lossless-cut). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19353",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19353 (DedeCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19364",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19364 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19373",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19373 (PhialsBasement KoboldCPP-MCP-Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-31842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-31842 (Tinyproxy Project Tinyproxy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66297 (livebook-dev livebook). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66757",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66757 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66881 (livebook-dev livebook). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-35384",
      "detail": "RESCORED — CVE-2023-35384 (Microsoft Windows 10 Version 1507). CVSS 5.4 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-35391",
      "detail": "RESCORED — CVE-2023-35391 (Microsoft .NET 6.0). CVSS 6.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36741",
      "detail": "RESCORED — CVE-2023-36741 (Microsoft Edge (Chromium-based)). CVSS 8.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36769",
      "detail": "RESCORED — CVE-2023-36769 (Microsoft Office 2019). CVSS 4.6 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36873",
      "detail": "RESCORED — CVE-2023-36873 (Microsoft .NET Framework 3.5 and 4.6.2). CVSS 7.4 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36897",
      "detail": "RESCORED — CVE-2023-36897 (Microsoft 365 Apps for Enterprise). CVSS 8.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36903",
      "detail": "RESCORED — CVE-2023-36903 (Microsoft Windows 10 Version 1507). CVSS 7.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36905",
      "detail": "RESCORED — CVE-2023-36905 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36906",
      "detail": "RESCORED — CVE-2023-36906 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36907",
      "detail": "RESCORED — CVE-2023-36907 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-36913",
      "detail": "RESCORED — CVE-2023-36913 (Microsoft Windows 10 Version 1507). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-38186",
      "detail": "RESCORED — CVE-2023-38186 (Microsoft Windows 10 Version 21H2). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-0565",
      "detail": "RESCORED — CVE-2024-0565 (Linux kernel). CVSS 6.8 → 7.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-0775",
      "detail": "RESCORED — CVE-2024-0775 (Linux kernel). CVSS 6.7 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-21343",
      "detail": "RESCORED — CVE-2024-21343 (Microsoft Windows 10 Version 1507). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-21416",
      "detail": "RESCORED — CVE-2024-21416 (Microsoft Windows 10 Version 1809). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-21489",
      "detail": "RESCORED — CVE-2024-21489 (uplot). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-37337",
      "detail": "RESCORED — CVE-2024-37337 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-37341",
      "detail": "RESCORED — CVE-2024-37341 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-37342",
      "detail": "RESCORED — CVE-2024-37342 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-37980",
      "detail": "RESCORED — CVE-2024-37980 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38194",
      "detail": "RESCORED — CVE-2024-38194 (Microsoft Azure Web Apps). CVSS 8.4 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38216",
      "detail": "RESCORED — CVE-2024-38216 (Microsoft Azure Stack Hub). CVSS 8.2 → 9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38225",
      "detail": "RESCORED — CVE-2024-38225 (Microsoft Dynamics 365 Business Central 2023 Release Wave 1). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38230",
      "detail": "RESCORED — CVE-2024-38230 (Microsoft Windows Server 2012 R2). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38231",
      "detail": "RESCORED — CVE-2024-38231 (Microsoft Windows Server 2008  Service Pack 2). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38240",
      "detail": "RESCORED — CVE-2024-38240 (Microsoft Windows 10 Version 1507). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38254",
      "detail": "RESCORED — CVE-2024-38254 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 6.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-38258",
      "detail": "RESCORED — CVE-2024-38258 (Microsoft Windows Server 2008  Service Pack 2). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43455",
      "detail": "RESCORED — CVE-2024-43455 (Microsoft Windows Server 2008  Service Pack 2). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43460",
      "detail": "RESCORED — CVE-2024-43460 (Microsoft Dynamics 365 Business Central Online). CVSS 8.1 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43474",
      "detail": "RESCORED — CVE-2024-43474 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43476",
      "detail": "RESCORED — CVE-2024-43476 (Microsoft Dynamics 365 (on-premises) version 9.1). CVSS 7.6 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43489",
      "detail": "RESCORED — CVE-2024-43489 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43496",
      "detail": "RESCORED — CVE-2024-43496 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38525",
      "detail": "RESCORED — CVE-2025-38525 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19375",
      "detail": "RESCORED — CVE-2026-19375 (dmitriiweb article-scraper-mcp). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19376",
      "detail": "RESCORED — CVE-2026-19376 (Uasoft Badaso). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19378",
      "detail": "RESCORED — CVE-2026-19378 (code-projects Task Management System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48618",
      "detail": "RESCORED — CVE-2026-48618 (nodejs node). CVSS 7.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-8037",
      "detail": "RESCORED — CVE-2026-8037 (Progress Software LoadMaster). CVSS 9.6 → 9.8 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
