{
  "day": "2026-08-11",
  "boundary": "UTC calendar day",
  "published_count": 933,
  "by_severity": {
    "CRITICAL": 60,
    "HIGH": 525,
    "MEDIUM": 325,
    "LOW": 23
  },
  "kev_count": 3,
  "exploit_reference_count": 2,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-72898",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.104,
      "epss_percentile": 0.95354,
      "kev": true,
      "kev_due_at": "2026-08-14",
      "vendor": "Metabase",
      "product": "Metabase",
      "cwe": "CWE-89",
      "title": "Metabase SQL injection via password reset endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72898"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-20349",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00874,
      "epss_percentile": 0.5613,
      "kev": true,
      "kev_due_at": "2026-08-14",
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-244",
      "title": "Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20349"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-68820",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26197,
      "kev": true,
      "kev_due_at": "2026-08-25",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68820"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-61358",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0368,
      "epss_percentile": 0.88779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-59",
      "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61358"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-66804",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.03423,
      "epss_percentile": 0.87949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 22H2",
      "cwe": "CWE-284",
      "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66804"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-62696",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.03175,
      "epss_percentile": 0.87007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62696"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-65775",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02446,
      "epss_percentile": 0.83044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65775"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-62832",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02365,
      "epss_percentile": 0.82447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-59",
      "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62832"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-72603",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02127,
      "epss_percentile": 0.8045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wg-easy",
      "product": "wg-easy",
      "cwe": "CWE-78",
      "title": "wg-easy wg-easy - OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72603"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-48362",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02071,
      "epss_percentile": 0.79905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-78",
      "title": "ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48362"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-61930",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01952,
      "epss_percentile": 0.78634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61930"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-62741",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01952,
      "epss_percentile": 0.78633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62741"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-62713",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0195,
      "epss_percentile": 0.78608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62713"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-64901",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01908,
      "epss_percentile": 0.78111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64901"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-66805",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01906,
      "epss_percentile": 0.78084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66805"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-66808",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01906,
      "epss_percentile": 0.78084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66808"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-62783",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01829,
      "epss_percentile": 0.77116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62783"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-62888",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01829,
      "epss_percentile": 0.77116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62888"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-62893",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01784,
      "epss_percentile": 0.76518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62893"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-65665",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01706,
      "epss_percentile": 0.75438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server 2019",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65665"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-59124",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01684,
      "epss_percentile": 0.75125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft HPC Pack 2019",
      "cwe": "CWE-502",
      "title": "Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59124"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-14863",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01671,
      "epss_percentile": 0.74914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FileRun",
      "product": "FileRun",
      "cwe": "CWE-78",
      "title": "FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14863"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-46670",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01652,
      "epss_percentile": 0.74628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki: Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46670"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-12571",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01632,
      "epss_percentile": 0.74339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zohocorp",
      "product": "manageengine_ddi_central",
      "cwe": "CWE-287",
      "title": "Authentication Bypass Leading to Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12571"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-61348",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0159,
      "epss_percentile": 0.73679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61348"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-61929",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01548,
      "epss_percentile": 0.73037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61929"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-65788",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01548,
      "epss_percentile": 0.73038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65788"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-62766",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01522,
      "epss_percentile": 0.72586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-415",
      "title": "Windows Kerberos Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62766"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-63514",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01517,
      "epss_percentile": 0.72514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63514"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-65658",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01385,
      "epss_percentile": 0.70029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65658"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-65663",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01385,
      "epss_percentile": 0.70029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65663"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-63516",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01346,
      "epss_percentile": 0.69181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63516"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-73034",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01334,
      "epss_percentile": 0.68889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eosphoros-ai",
      "product": "DB-GPT",
      "cwe": "CWE-22",
      "title": "DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73034"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-62912",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01315,
      "epss_percentile": 0.68445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-502",
      "title": "Microsoft Exchange Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62912"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-59132",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0131,
      "epss_percentile": 0.68354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Windows TCP/IP Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59132"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-63520",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.01304,
      "epss_percentile": 0.68236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-20",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63520"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-71362",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01301,
      "epss_percentile": 0.68167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71362"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-70321",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01255,
      "epss_percentile": 0.6712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70321"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-66148",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01168,
      "epss_percentile": 0.64853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "GMS",
      "cwe": "CWE-94",
      "title": "An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66148"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-54113",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01126,
      "epss_percentile": 0.63721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-770",
      "title": "Remote Procedure Call Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54113"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-62898",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01112,
      "epss_percentile": 0.63366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-416",
      "title": "Microsoft QUIC Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62898"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-62901",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01057,
      "epss_percentile": 0.61806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-606",
      "title": ".NET Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62901"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-11739",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01053,
      "epss_percentile": 0.61686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "MR60",
      "cwe": "CWE-78",
      "title": "Command injection vulnerability in some NETGEAR Nighthawk devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11739"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-66147",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01049,
      "epss_percentile": 0.61561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "GMS",
      "cwe": "CWE-94",
      "title": "An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66147"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-59138",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01042,
      "epss_percentile": 0.6138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59138"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-61345",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01042,
      "epss_percentile": 0.61379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61345"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-16053",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00991,
      "epss_percentile": 0.59774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine M365 Manager Plus",
      "cwe": "CWE-23",
      "title": "Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16053"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-64921",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00975,
      "epss_percentile": 0.59307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-306",
      "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64921"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-45618",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00954,
      "epss_percentile": 0.58613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-94",
      "title": "LiquidJS is Vulnerable to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45618"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-62818",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00953,
      "epss_percentile": 0.58565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62818"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-62702",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00943,
      "epss_percentile": 0.58258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-476",
      "title": "Windows Graphics Kernel Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62702"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-47299",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00939,
      "epss_percentile": 0.58156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Monitor Agent Linux Extension",
      "cwe": "CWE-77",
      "title": "Azure Monitor Agent Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47299"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-59133",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00921,
      "epss_percentile": 0.57529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows App Client for Windows Desktop",
      "cwe": "CWE-250",
      "title": "Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59133"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-62815",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00916,
      "epss_percentile": 0.57408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Microsoft QUIC Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62815"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-62784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00915,
      "epss_percentile": 0.57351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62784"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-62800",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00915,
      "epss_percentile": 0.5735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62800"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-65815",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0091,
      "epss_percentile": 0.57201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dynamics 365 (on-premises) version 9.1",
      "cwe": "CWE-502",
      "title": "Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65815"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-62878",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00887,
      "epss_percentile": 0.5649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62878"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2025-31114",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00875,
      "epss_percentile": 0.5617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lllyasviel",
      "product": "Fooocus",
      "cwe": "CWE-95",
      "title": "Fooocus webui vulnerable to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31114"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-18129",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00871,
      "epss_percentile": 0.56013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Endpoint Manager",
      "cwe": "CWE-295",
      "title": "Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18129"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-61918",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00869,
      "epss_percentile": 0.55959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61918"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-62782",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00868,
      "epss_percentile": 0.55924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows SMB Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62782"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-47285",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00868,
      "epss_percentile": 0.55924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-77",
      "title": "Visual Studio Code Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47285"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-62837",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00861,
      "epss_percentile": 0.55713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-23",
      "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62837"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-5917",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00859,
      "epss_percentile": 0.55653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libgit2",
      "product": "libgit2",
      "cwe": "CWE-78",
      "title": "libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5917"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-65681",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00853,
      "epss_percentile": 0.55447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65681"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-70327",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00853,
      "epss_percentile": 0.55423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70327"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-70328",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00853,
      "epss_percentile": 0.55423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70328"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-58639",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00835,
      "epss_percentile": 0.54869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-918",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58639"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-19091",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00829,
      "epss_percentile": 0.54691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paoltaia",
      "product": "GeoDirectory – WP Business Directory Plugin and Classified Listings Directory",
      "cwe": "CWE-22",
      "title": "GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19091"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-61924",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00829,
      "epss_percentile": 0.547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61924"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-61921",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00829,
      "epss_percentile": 0.547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61921"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-11814",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00825,
      "epss_percentile": 0.54556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "BE9300",
      "cwe": "CWE-295",
      "title": "Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11814"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-62785",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0082,
      "epss_percentile": 0.5441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62785"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-73218",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00818,
      "epss_percentile": 0.54329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cursor",
      "product": "cursor",
      "cwe": "CWE-269",
      "title": "Cursor: Sandbox escape via launching privileged containers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73218"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-49179",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00814,
      "epss_percentile": 0.54189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-77",
      "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49179"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-48385",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.008,
      "epss_percentile": 0.53725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-78",
      "title": "ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48385"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-57104",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00791,
      "epss_percentile": 0.53461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Storage Explorer",
      "cwe": "CWE-79",
      "title": "Azure Storage Explorer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57104"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-58612",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00786,
      "epss_percentile": 0.53294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "PowerShell 7.4",
      "cwe": "CWE-918",
      "title": "PowerShell Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58612"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-18125",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00775,
      "epss_percentile": 0.52938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Endpoint Manager",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18125"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-50516",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00774,
      "epss_percentile": 0.52931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Kubernetes Service",
      "cwe": "CWE-306",
      "title": "Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50516"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-40375",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00769,
      "epss_percentile": 0.5274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dynamics 365 Business Central 2024 Release Wave 2",
      "cwe": "CWE-862",
      "title": "Microsoft Dynamics Business Central Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40375"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-62902",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00762,
      "epss_percentile": 0.52543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 8.0",
      "cwe": "CWE-829",
      "title": ".NET Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62902"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-70337",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00758,
      "epss_percentile": 0.52393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "PowerShell 7.4",
      "cwe": "CWE-23",
      "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70337"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-65660",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00742,
      "epss_percentile": 0.51848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-94",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65660"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-70306",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00733,
      "epss_percentile": 0.51569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft Office SharePoint Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70306"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-62827",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0073,
      "epss_percentile": 0.51423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-287",
      "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62827"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-69223",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00728,
      "epss_percentile": 0.51351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-918",
      "title": "Apache Allura: Server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69223"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-58231",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00726,
      "epss_percentile": 0.51269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Commerce Cloud (Data Hub Adapter)",
      "cwe": "CWE-94",
      "title": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58231"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-62911",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00717,
      "epss_percentile": 0.50948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-294",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62911"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-62792",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00708,
      "epss_percentile": 0.50655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows TCP/IP Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62792"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-62899",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00706,
      "epss_percentile": 0.50553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-444",
      "title": ".NET Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62899"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-72713",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00702,
      "epss_percentile": 0.50412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBMB",
      "product": "XAgent",
      "cwe": "CWE-22",
      "title": "XAgent Path Traversal Arbitrary File Read via /workspace/file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72713"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-70324",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00696,
      "epss_percentile": 0.50187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-918",
      "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70324"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-48386",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00696,
      "epss_percentile": 0.50205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-327",
      "title": "ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48386"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-59113",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00694,
      "epss_percentile": 0.50142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-862",
      "title": "Visual Studio Code Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59113"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-72538",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00692,
      "epss_percentile": 0.50066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrefectHQ",
      "product": "Prefect",
      "cwe": "CWE-88",
      "title": "PrefectHQ Prefect - Argument Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72538"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-48384",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00689,
      "epss_percentile": 0.49967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48384"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-68819",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00684,
      "epss_percentile": 0.49758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Network File System Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68819"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-66301",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00683,
      "epss_percentile": 0.49715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dynamics 365 (on-premises) version 9.1",
      "cwe": "CWE-200",
      "title": "Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66301"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-62910",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00678,
      "epss_percentile": 0.49539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-99",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62910"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-72551",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00668,
      "epss_percentile": 0.49111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apioo",
      "product": "Fusio",
      "cwe": "CWE-78",
      "title": "Apioo Fusio - Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72551"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-72556",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00668,
      "epss_percentile": 0.49111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZoneMinder",
      "product": "ZoneMinder",
      "cwe": "CWE-78",
      "title": "ZoneMinder ZoneMinder - Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72556"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-62790",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00664,
      "epss_percentile": 0.48958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62790"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-65769",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00661,
      "epss_percentile": 0.48868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams for iOS",
      "cwe": "CWE-200",
      "title": "Microsoft Teams iOS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65769"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-72748",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00661,
      "epss_percentile": 0.48868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-306",
      "title": "AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72748"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-58115",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00654,
      "epss_percentile": 0.48552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SIMATIC IoT2050 Advanced",
      "cwe": "CWE-306",
      "title": "A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58115"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-65794",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00651,
      "epss_percentile": 0.48453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows SMB Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65794"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-65813",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0065,
      "epss_percentile": 0.48394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-918",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65813"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-71398",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00639,
      "epss_percentile": 0.47881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71398"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-70329",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00638,
      "epss_percentile": 0.47834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-190",
      "title": "Microsoft Outlook Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70329"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-48413",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00628,
      "epss_percentile": 0.47406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-79",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48413"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-62839",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00626,
      "epss_percentile": 0.47328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-522",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62839"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-61363",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00625,
      "epss_percentile": 0.47265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61363"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-59134",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00624,
      "epss_percentile": 0.47226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59134"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-13457",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00623,
      "epss_percentile": 0.47188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "instawp",
      "product": "InstaWP Connect – 1-click WP Staging & Migration",
      "cwe": "CWE-434",
      "title": "InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13457"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-62822",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0062,
      "epss_percentile": 0.47015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows GDI+ Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62822"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-62913",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00618,
      "epss_percentile": 0.46953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-122",
      "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62913"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-48440",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00618,
      "epss_percentile": 0.46936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-122",
      "title": "ColdFusion | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48440"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-62824",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00613,
      "epss_percentile": 0.46666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62824"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-65768",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00612,
      "epss_percentile": 0.4662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams for Android",
      "cwe": "CWE-22",
      "title": "Microsoft Teams Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65768"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-62882",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00601,
      "epss_percentile": 0.4613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-522",
      "title": "Microsoft Outlook Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62882"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-62795",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00595,
      "epss_percentile": 0.45837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62795"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-70336",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00594,
      "epss_percentile": 0.45808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-94",
      "title": "Visual Studio Code Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70336"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-70340",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0059,
      "epss_percentile": 0.45651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure CycleCloud 8.9.1",
      "cwe": "CWE-862",
      "title": "Azure CycleCloud Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70340"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-65791",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00588,
      "epss_percentile": 0.45537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65791"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-21273",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00583,
      "epss_percentile": 0.45306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21273"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-57105",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0058,
      "epss_percentile": 0.45172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server 2019",
      "cwe": "CWE-79",
      "title": "Microsoft Office SharePoint Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57105"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-13716",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00579,
      "epss_percentile": 0.45091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arcadia Technology, LLC",
      "product": "Crafty Controller",
      "cwe": "CWE-35",
      "title": "Path Traversal: '.../...//' in Crafty Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13716"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-62819",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00579,
      "epss_percentile": 0.45106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62819"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-65806",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00577,
      "epss_percentile": 0.44992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure CycleCloud 8.9.2",
      "cwe": "CWE-862",
      "title": "Azure CycleCloud Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65806"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-70326",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00576,
      "epss_percentile": 0.4497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-918",
      "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70326"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-48375",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00576,
      "epss_percentile": 0.44966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-863",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48375"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-62750",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00574,
      "epss_percentile": 0.44873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-187",
      "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62750"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-27302",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00573,
      "epss_percentile": 0.44835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27302"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-62889",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.44155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62889"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-17061",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00557,
      "epss_percentile": 0.43988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "SIMULIA Execution Engine",
      "cwe": "CWE-502",
      "title": "Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17061"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-62817",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00557,
      "epss_percentile": 0.44028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-787",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62817"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-62900",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00546,
      "epss_percentile": 0.43462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-212",
      "title": ".NET Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62900"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-65679",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00545,
      "epss_percentile": 0.43411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65679"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-63512",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00545,
      "epss_percentile": 0.43359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-863",
      "title": "Microsoft SharePoint Server Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63512"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-62823",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00543,
      "epss_percentile": 0.43261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62823"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-72781",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-693",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72781"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-62814",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00537,
      "epss_percentile": 0.42975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62814"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-48397",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00536,
      "epss_percentile": 0.42892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-502",
      "title": "Lightroom Classic | Deserialization of Untrusted Data (CWE-502)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48397"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-47704",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00535,
      "epss_percentile": 0.42883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-639",
      "title": "TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows unauthorized control of another bot's waiting session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47704"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-48414",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00533,
      "epss_percentile": 0.4275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-79",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48414"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-62872",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft .NET Framework 3.5",
      "cwe": "CWE-863",
      "title": ".NET Framework Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62872"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-13738",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00526,
      "epss_percentile": 0.42349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-863",
      "title": "Improper Authorization Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13738"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-65811",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00514,
      "epss_percentile": 0.41643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Power BI Report Server",
      "cwe": "CWE-20",
      "title": "Power BI Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65811"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-62787",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00511,
      "epss_percentile": 0.41413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62787"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-62781",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "RPC Runtime Library Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62781"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-65796",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65796"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-48438",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-476",
      "title": "CAI Content Credentials | NULL Pointer Dereference (CWE-476)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48438"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-48439",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48439"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-44758",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00507,
      "epss_percentile": 0.41164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Manufacturing Integration and Intelligence",
      "cwe": "CWE-94",
      "title": "Code Injection vulnerability in Manufacturing Integration and Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44758"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-62778",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00506,
      "epss_percentile": 0.4114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62778"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-48376",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.41042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-116",
      "title": "ColdFusion | Improper Encoding or Escaping of Output (CWE-116)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48376"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-16230",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00496,
      "epss_percentile": 0.40547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11",
      "product": "Formidable Digital Signatures",
      "cwe": "CWE-23",
      "title": "Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16230"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-48416",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00495,
      "epss_percentile": 0.40485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48416"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-48411",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00494,
      "epss_percentile": 0.40404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48411"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-72602",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.40138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncFuncAI",
      "product": "deepwiki-open",
      "cwe": "CWE-22",
      "title": "AsyncFuncAI deepwiki-open - Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72602"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-61920",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00484,
      "epss_percentile": 0.39794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61920"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-62915",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00484,
      "epss_percentile": 0.39764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-862",
      "title": "Microsoft Exchange Server Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62915"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2024-14042",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00482,
      "epss_percentile": 0.39682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14042"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2024-14043",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00482,
      "epss_percentile": 0.39682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14043"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-62715",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0048,
      "epss_percentile": 0.39576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62715"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-62718",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0048,
      "epss_percentile": 0.39575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62718"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-62742",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0048,
      "epss_percentile": 0.39575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62742"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-65675",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00478,
      "epss_percentile": 0.39443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Visual Studio Code CoPilot Chat Extension",
      "cwe": "CWE-862",
      "title": "CoPilot Chat Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65675"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-48381",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-89",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48381"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-15565",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-120",
      "title": "Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15565"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-19425",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Win Men Intermational",
      "product": "Travel Agency Management System",
      "cwe": "CWE-89",
      "title": "Win Men Intermational｜Travel Agency Management System - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19425"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-72770",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n before 1.123.67 Path Traversal via Git Node Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72770"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2016-20097",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.3888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaver Network Co., Ltd.",
      "product": "E-cology 8.0",
      "cwe": "CWE-89",
      "title": "Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20097"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-62714",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00468,
      "epss_percentile": 0.38722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62714"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-62716",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00468,
      "epss_percentile": 0.38722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62716"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-62720",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00468,
      "epss_percentile": 0.38722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62720"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-29035",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "civetweb",
      "product": "civetweb",
      "cwe": "CWE-787",
      "title": "CivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29035"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-70314",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00467,
      "epss_percentile": 0.38678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70314"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-70335",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-78",
      "title": "GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70335"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2022-50997",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaver Network Co., Ltd.",
      "product": "E-cology 9.0",
      "cwe": "CWE-89",
      "title": "Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-50997"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-69109",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Siemens License Server (SLS)",
      "cwe": "CWE-35",
      "title": "A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69109"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-70355",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server 2019",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70355"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-63530",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00459,
      "epss_percentile": 0.38198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63530"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-69320",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-78",
      "title": "Visual Studio Code Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69320"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-72548",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "OpenSign",
      "cwe": "CWE-200",
      "title": "OpenSignLabs OpenSign - Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72548"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-72543",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "OpenSign",
      "cwe": "CWE-639",
      "title": "OpenSignLabs OpenSign - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72543"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-61350",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00449,
      "epss_percentile": 0.3751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61350"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-72778",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-915",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72778"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-68797",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00447,
      "epss_percentile": 0.37376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68797"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-73232",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ffuf",
      "product": "ffuf",
      "cwe": "CWE-409",
      "title": "ffuf denial of service (OOM) via HTTP response decompression bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73232"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-64900",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00446,
      "epss_percentile": 0.37317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64900"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-65789",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65789"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-71331",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-190",
      "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71331"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-62820",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62820"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-65767",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams for Android",
      "cwe": "CWE-79",
      "title": "Microsoft Teams for Android Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65767"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-69102",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "MaxKey",
      "cwe": "CWE-798",
      "title": "MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69102"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-15562",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-190",
      "title": "Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15562"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-47922",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.36878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-918",
      "title": "CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47922"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-34265",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0044,
      "epss_percentile": 0.36781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver and ABAP Platform",
      "cwe": "CWE-787",
      "title": "Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34265"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-15560",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00439,
      "epss_percentile": 0.36743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-829",
      "title": "Openjdk-orb: unauthed class loading via iiop in eap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15560"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-65657",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00439,
      "epss_percentile": 0.36726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65657"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-54123",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00438,
      "epss_percentile": 0.36644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Defender for Endpoint for Mac",
      "cwe": "CWE-200",
      "title": "Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54123"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-62917",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00438,
      "epss_percentile": 0.36646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-20",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62917"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-73032",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.3662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "papersgpt",
      "product": "papersgpt-for-zotero",
      "cwe": "CWE-94",
      "title": "PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73032"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-15567",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-789",
      "title": "Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listener",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15567"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-54981",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Python extension for Visual Studio Code",
      "cwe": "CWE-829",
      "title": "Visual Studio Code Python Extension Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54981"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-66145",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.3631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "GMS",
      "cwe": "CWE-94",
      "title": "An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66145"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-65807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-843",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65807"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-72552",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dub",
      "product": "Dub",
      "cwe": "CWE-918",
      "title": "Dub Dub - Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72552"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-61352",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61352"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-39452",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.35872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Transfer Learning Tool",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39452"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-13737",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.35609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-863",
      "title": "Command Restriction Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13737"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-70348",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00425,
      "epss_percentile": 0.3564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-59",
      "title": "Windows Management Services Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70348"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-72535",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chaskiq",
      "product": "Chaskiq",
      "cwe": "CWE-306",
      "title": "Chaskiq Chaskiq - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72535"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-72536",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chaskiq",
      "product": "Chaskiq",
      "cwe": "CWE-306",
      "title": "Chaskiq Chaskiq - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72536"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-73214",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.3549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-400",
      "title": "coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73214"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-72712",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00423,
      "epss_percentile": 0.35512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nmap Project",
      "product": "Nmap",
      "cwe": "CWE-835",
      "title": "Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72712"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-73210",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lookyloo",
      "product": "PlaywrightCapture",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery via Favicon Retrieval in Lookyloo PlaywrightCapture",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73210"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-68798",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68798"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-51584",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00418,
      "epss_percentile": 0.3505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-287",
      "title": "An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51584"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-21279",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21279"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-54984",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54984"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-18247",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00418,
      "epss_percentile": 0.35018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlackBerry",
      "product": "BlackBerry AtHoc IWS",
      "cwe": "CWE-79",
      "title": "DOM-Based Cross-Site Scripting in BlackBerry AtHoc Web Portals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18247"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-72550",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Friendica",
      "product": "Friendica",
      "cwe": "CWE-89",
      "title": "Friendica Friendica - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72550"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-71217",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-20",
      "title": "Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71217"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-66806",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00416,
      "epss_percentile": 0.34906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-193",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66806"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-62869",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.34577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-345",
      "title": "Azure Entra ID Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62869"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-14180",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-444",
      "title": "Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14180"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-64897",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64897"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-64902",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64902"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-64916",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64916"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-64922",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64922"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-19424",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inventec Appliances",
      "product": "Chiline Cloud",
      "cwe": "CWE-639",
      "title": "Inventec Appliances｜Chiline Cloud - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19424"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-71467",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-287",
      "title": "Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71467"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-53413",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Clients",
      "cwe": "CWE-787",
      "title": "Zoom Clients - Buffer Over-write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53413"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-62699",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00409,
      "epss_percentile": 0.34231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62699"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-72920",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00408,
      "epss_percentile": 0.34207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-306",
      "title": "SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72920"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-18692",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18692"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-73216",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-400",
      "title": "coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73216"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-69306",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-636",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69306"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-68812",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68812"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-68814",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68814"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-68817",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68817"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-19556",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19556"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-19559",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19559"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-19560",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19560"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-72533",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.3312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Portainer",
      "product": "Portainer CE",
      "cwe": "CWE-287",
      "title": "Portainer Portainer CE - Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72533"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-72545",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "OpenSign",
      "cwe": "CWE-639",
      "title": "OpenSignLabs OpenSign - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72545"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-62871",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 8.0",
      "cwe": "CWE-787",
      "title": ".NET Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62871"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-62886",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-190",
      "title": ".NET Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62886"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-73211",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chocobozzz",
      "product": "PeerTube",
      "cwe": "CWE-89",
      "title": "PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73211"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-62816",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62816"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-58641",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-190",
      "title": ".NET Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58641"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-58651",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58651"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-64914",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64914"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-68806",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-787",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68806"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-18127",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Endpoint Manager",
      "cwe": "CWE-73",
      "title": "External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18127"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-4757",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.3232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axis Communications AB",
      "product": "AXIS OS",
      "cwe": "CWE-732",
      "title": "A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4757"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-48436",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.32273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48436"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-53415",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Clients",
      "cwe": "CWE-416",
      "title": "Zoom Clients - Use After Free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53415"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-72767",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-78",
      "title": "n8n before 1.123.67 Remote Code Execution via Git node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72767"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-59128",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59128"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-59137",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows Event Logging Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59137"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-61347",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Event Logging Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61347"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-61360",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-822",
      "title": "Windows GDI Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61360"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-61933",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-125",
      "title": "Windows DWM Core Library Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61933"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-62703",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-125",
      "title": "Windows DWM Core Library Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62703"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-62709",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows GDI+ Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62709"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-62730",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62730"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-62738",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62738"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-62740",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows Imaging Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62740"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-62743",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62743"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-62746",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62746"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-73226",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-913",
      "title": "Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73226"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-73080",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-918",
      "title": "SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73080"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-71218",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-789",
      "title": "Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71218"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-73241",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-287",
      "title": "FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73241"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-72773",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.3143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n before 2.32.1 Path Traversal via computer-use search_files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72773"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-62712",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62712"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-62735",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62735"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-48056",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00379,
      "epss_percentile": 0.31224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-20",
      "title": "Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48056"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-47705",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00378,
      "epss_percentile": 0.31082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-1236",
      "title": "TypeBot vulnerable to CSV injection in result export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47705"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-65785",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-400",
      "title": "Windows DHCP Client Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65785"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-63525",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-197",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63525"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-58236",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver Application Server ABAP and ABAP Platform",
      "cwe": "CWE-78",
      "title": "OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58236"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-70315",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.3082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70315"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-70316",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.3082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Powerpoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70316"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-70319",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70319"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-70320",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Powerpoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70320"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-70322",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Powerpoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70322"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-70323",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70323"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-70325",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Powerpoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70325"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-72764",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-668",
      "title": "n8n before 1.123.67 Module Cache Poisoning via Code Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72764"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-72742",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stanford NLP",
      "product": "DSPy",
      "cwe": "CWE-73",
      "title": "DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72742"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-61368",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Hyper-V Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61368"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-72765",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.3037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-94",
      "title": "n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72765"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-62803",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62803"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-62807",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62807"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-59136",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59136"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-73031",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GramSearch",
      "product": "telegram-search",
      "cwe": "CWE-79",
      "title": "telegram-search Stored XSS via v-html in MessageList.vue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73031"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-56721",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-639",
      "title": "CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56721"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-62688",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62688"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-62698",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62698"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-73088",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browserslist",
      "product": "browserslist",
      "cwe": "CWE-248",
      "title": "Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73088"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-62745",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62745"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-73089",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browserslist",
      "product": "browserslist",
      "cwe": "CWE-770",
      "title": "Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73089"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-62842",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62842"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-63517",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63517"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-70318",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70318"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-70317",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-908",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70317"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-72971",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-59",
      "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72971"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-65656",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-77",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65656"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-59119",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "PowerShell 7.4",
      "cwe": "CWE-276",
      "title": "PowerShell Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59119"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-62829",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server 2019",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62829"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-73069",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.2871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-89",
      "title": "Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73069"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-62761",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62761"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-72600",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Idurar",
      "product": "IDURAR ERP CRM",
      "cwe": "CWE-284",
      "title": "Idurar IDURAR ERP CRM - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72600"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-72601",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CSZ CMS",
      "product": "CSZ CMS",
      "cwe": "CWE-284",
      "title": "CSZ CMS CSZ CMS - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72601"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-72549",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "OpenSign",
      "cwe": "CWE-200",
      "title": "OpenSignLabs OpenSign - Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72549"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-15426",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acyba",
      "product": "AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress",
      "cwe": "CWE-269",
      "title": "AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15426"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-66802",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66802"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-63513",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63513"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-63515",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63515"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-63518",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63518"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-63519",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63519"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-65664",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65664"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-66807",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66807"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-68794",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68794"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-68804",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-197",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68804"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-40130",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAPSPrint Service",
      "cwe": "CWE-121",
      "title": "Memory Corruption vulnerability in SAPSPrint Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40130"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-73242",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73242"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-15561",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-770",
      "title": "Undertow-core: oom via missing limits in chunked trailer in eap's undertow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15561"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-48415",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48415"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-73246",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-200",
      "title": "Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73246"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-63524",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63524"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-63528",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63528"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-63529",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63529"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-63531",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63531"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-64899",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64899"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-64917",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64917"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-68799",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-908",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68799"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-68802",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68802"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-68808",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68808"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-68813",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68813"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-24329",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Fuse 7",
      "cwe": "CWE-91",
      "title": "Wildfly-core: wildfly core: denial of service via malformed payload injection by an authenticated administrative user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24329"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-19434",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maalfer",
      "product": "Pentestify",
      "cwe": "CWE-79",
      "title": "Stored Cross-site Scripting in Pentestify finding severity field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19434"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-18706",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18706"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-48494",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-639",
      "title": "TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session ids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48494"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-73219",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cvat-ai",
      "product": "cvat",
      "cwe": "CWE-1288",
      "title": "CVAT: Denial of service with regards to automatic annotation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73219"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-73244",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.2727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kekingcn",
      "product": "kkFileView",
      "cwe": "CWE-22",
      "title": "kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73244"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-63526",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63526"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-63532",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-190",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63532"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-64898",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64898"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-64903",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-190",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64903"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-64907",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64907"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-64909",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-191",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64909"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-64910",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-822",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64910"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-64911",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-190",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64911"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-68816",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68816"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-73224",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-78",
      "title": "Electerm check folder size function may get attacked by unsafe folder name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73224"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-11734",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00339,
      "epss_percentile": 0.26942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "MR70",
      "cwe": "CWE-121",
      "title": "Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11734"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-72599",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e107",
      "product": "e107",
      "cwe": "CWE-89",
      "title": "e107 e107 - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72599"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-59130",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "AMD Zen Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59130"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-73078",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-77",
      "title": "Vim: Arbitrary Code Execution via Netrw Menu Construction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73078"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-70338",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "PowerShell 7.4",
      "cwe": "CWE-94",
      "title": "Microsoft PowerShell Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70338"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-62914",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-79",
      "title": "Microsoft Exchange Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62914"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-61359",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows Storage Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61359"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-62797",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62797"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-62811",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62811"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-72554",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ladybird Web Solution",
      "product": "Faveo Helpdesk",
      "cwe": "CWE-284",
      "title": "Ladybird Web Solution Faveo Helpdesk - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72554"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-62737",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-822",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62737"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-73215",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-400",
      "title": "The coturn server can end in a state where it does not accept more requests with \"even-port\" enabled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73215"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-48483",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-918",
      "title": "TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48483"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-73156",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-79",
      "title": "cti-transmute Sunburst and Treemap Tooltips Allow Cross-Site Scripting via Crafted Conversion Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73156"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-62897",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-190",
      "title": ".NET Framework Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62897"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-72557",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cockpit CMS",
      "product": "Cockpit CMS",
      "cwe": "CWE-434",
      "title": "Cockpit CMS Cockpit CMS - Unrestricted File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72557"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-58650",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-639",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58650"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-69278",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-863",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69278"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-48813",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "david-a-wheeler",
      "product": "flawfinder",
      "cwe": "CWE-74",
      "title": "Flawfinder output manipulation via untrusted filenames and source text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48813"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-11733",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00326,
      "epss_percentile": 0.25585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RAX41",
      "cwe": "CWE-121",
      "title": "Buffer overflow vulnerability in some NETGEAR Nighthawk routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11733"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-18972",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-290",
      "title": "Velociraptor authenticated identity-spoofing vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18972"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-20702",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20702"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-65661",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65661"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-68793",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68793"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-68795",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68795"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-68796",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68796"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-68800",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68800"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-68801",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68801"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-68805",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68805"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-70313",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70313"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-62769",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62769"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-62881",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62881"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-72604",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.2546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intelliants",
      "product": "Subrion CMS",
      "cwe": "CWE-22",
      "title": "Intelliants Subrion CMS - Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72604"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-18697",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18697"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-61925",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-863",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61925"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-19539",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-862",
      "title": "IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19539"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-62721",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1220",
      "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62721"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-65673",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra Connect",
      "cwe": "CWE-89",
      "title": "Microsoft Entra Connect Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65673"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-73228",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.24965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "encode",
      "product": "django-rest-framework",
      "cwe": "CWE-400",
      "title": "Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73228"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-59135",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1390",
      "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59135"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-48802",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miguelgrinberg",
      "product": "python-engineio",
      "cwe": "CWE-770",
      "title": "python-engineio has unbound thread allocation that can cause denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48802"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-15606",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.2454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-862",
      "title": "Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15606"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-73243",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kekingcn",
      "product": "kkFileView",
      "cwe": "CWE-918",
      "title": "kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73243"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-20715",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "cwe": "CWE-20",
      "title": "Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20715"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-70130",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70130"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-70304",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70304"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-70330",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70330"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-62708",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62708"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-48766",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-200",
      "title": "TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48766"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-48767",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-200",
      "title": "Google Sheets OAuth access token disclosure to guest members via getAccessToken",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48767"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-69119",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Taubyte",
      "product": "tau",
      "cwe": "CWE-639",
      "title": "Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69119"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-48412",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00315,
      "epss_percentile": 0.24281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48412"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-66777",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-22",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66777"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-18640",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-22",
      "title": "Velociraptor directory traversal via the NewNotebook API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18640"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-11735",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00313,
      "epss_percentile": 0.24075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "R7000",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11735"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-11736",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00313,
      "epss_percentile": 0.24075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RAX20",
      "cwe": "CWE-20",
      "title": "Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11736"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-48763",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-862",
      "title": "TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48763"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-73217",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cursor",
      "product": "cursor",
      "cwe": "CWE-693",
      "title": "Cursor: Sandbox escape via tampered Python virtual environments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73217"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-62786",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62786"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-62793",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62793"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-62796",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62796"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-62798",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-822",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62798"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-65662",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows GDI Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65662"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-73223",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-22",
      "title": "electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73223"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-73225",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-22",
      "title": "electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73225"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-73227",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-22",
      "title": "electerm's RDP clipboard file download may parse unsafe file name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73227"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-59127",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59127"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-61353",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61353"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-61355",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61355"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-61357",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Application Information Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61357"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-61923",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61923"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-61926",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows USB Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61926"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-61932",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-843",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61932"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-61934",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61934"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-61937",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61937"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-62692",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62692"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-62695",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows Storage Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62695"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-62700",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62700"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-62701",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62701"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-62707",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62707"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-62710",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62710"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-62711",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62711"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-62717",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62717"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-62719",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62719"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-62722",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62722"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-62732",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62732"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-62747",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62747"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-62751",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-190",
      "title": "Windows Projected File System Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62751"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-62752",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kerberos Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62752"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-62754",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kerberos Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62754"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-62768",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62768"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-65787",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65787"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-70344",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70344"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-70346",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70346"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-70347",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70347"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-73079",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.2371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wei-Shaw",
      "product": "sub2api",
      "cwe": "CWE-22",
      "title": "Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73079"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-58243",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP ABAP Developer Tools",
      "cwe": "CWE-862",
      "title": "Privilege Escalation vulnerability in SAP ABAP Developer Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58243"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-13739",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13739"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-72605",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Swing Music",
      "product": "Swing Music",
      "cwe": "CWE-306",
      "title": "Swing Music Swing Music - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72605"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-72749",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n before 1.123.67 Prototype Pollution via Edit Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72749"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-72534",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.2338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Authentik Security",
      "product": "authentik",
      "cwe": "CWE-269",
      "title": "Authentik Security authentik - Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72534"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-19546",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-94",
      "title": "Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19546"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-72539",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Windmill Labs",
      "product": "Windmill",
      "cwe": "CWE-200",
      "title": "Windmill Labs Windmill - Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72539"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-18860",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-280",
      "title": "Velociraptor incorrect Org deletion permissions check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18860"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-10579",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-347",
      "title": "Picketlink-federation: auth bypass in picketlink saml unsolicited-response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10579"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-19557",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19557"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-63527",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63527"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-63533",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63533"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-64904",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-843",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64904"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-64905",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64905"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-64906",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64906"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-64908",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64908"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-64912",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64912"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-64915",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64915"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-64919",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64919"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-64920",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64920"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-68803",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-843",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68803"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-68807",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68807"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-68810",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-822",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68810"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-68811",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-843",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68811"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-68815",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68815"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-70311",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70311"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-73213",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.23046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-863",
      "title": "Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73213"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-18701",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-843",
      "title": "Type Confusion in MongoDB Query Subsystem Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18701"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-73160",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-918",
      "title": "cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73160"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-35502",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.2267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Extension for PyTorch",
      "cwe": "CWE-502",
      "title": "Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35502"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-65784",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65784"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-55676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cisagov",
      "product": "Malcolm",
      "cwe": "CWE-434",
      "title": "Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55676"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-62887",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62887"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-73081",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activepieces",
      "product": "activepieces",
      "cwe": "CWE-78",
      "title": "Activepieces: Remote Code Execution via Command Injection in Code Step Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73081"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-24330",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Fuse 7",
      "cwe": "CWE-434",
      "title": "Wildfly-core: wildfly: arbitrary file read via malicious archive deployment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24330"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-73247",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-918",
      "title": "Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73247"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-73086",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ai",
      "product": "nanoid",
      "cwe": "CWE-190",
      "title": "nanoid: Integer Overflow or Wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73086"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-6181",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axis Communications AB",
      "product": "AXIS OS",
      "cwe": "CWE-290",
      "title": "The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6181"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-71386",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-79",
      "title": "ColdFusion | Cross-site Scripting (XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71386"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-72774",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 1.123.67 Authentication Bypass via HTTP Request Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72774"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-70354",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-787",
      "title": ".NET Core Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70354"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-72537",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Authentik Security",
      "product": "authentik",
      "cwe": "CWE-269",
      "title": "Authentik Security authentik - Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72537"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-51583",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51583"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-56174",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-426",
      "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56174"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-62812",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62812"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-15563",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-306",
      "title": "Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15563"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-63521",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63521"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-18695",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Improper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18695"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-18638",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-476",
      "title": "Velociraptor server crash via the SetPassword API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18638"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-18699",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-476",
      "title": "Improper Input Validation in MongoDB Query Planner Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18699"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-18700",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18700"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-62909",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.2137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-252",
      "title": ".NET Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62909"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-65777",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-326",
      "title": "Active Directory Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65777"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-18696",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18696"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-68067",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.21019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-1390",
      "title": "Mira Hormone Monitor, Mira Android App Weak Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68067"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-59131",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.21025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": null,
      "title": "AMD Zen Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59131"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-18708",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-94",
      "title": "Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18708"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-72606",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pinry",
      "product": "Pinry",
      "cwe": "CWE-918",
      "title": "Pinry Pinry - Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72606"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-65680",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "OneDrive for MacOS",
      "cwe": "CWE-59",
      "title": "Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65680"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-44763",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Manufacturing Integration and Intelligence",
      "cwe": "CWE-22",
      "title": "Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44763"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-73212",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-284",
      "title": "coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73212"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-61936",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-862",
      "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61936"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-58248",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP BusinessObjects Business Intelligence",
      "cwe": "CWE-611",
      "title": "XML External Entity Injection in SAP BusinessObjects Business Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58248"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-71475",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-22",
      "title": "Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71475"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-65655",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0028,
      "epss_percentile": 0.20586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "Temporal UI Server",
      "cwe": "CWE-614",
      "title": "Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65655"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-48804",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miguelgrinberg",
      "product": "python-socketio",
      "cwe": "CWE-770",
      "title": "python-socketio: Binary attachment accumulation can cause denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48804"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-48809",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miguelgrinberg",
      "product": "python-engineio",
      "cwe": "CWE-770",
      "title": "python-engineio has possible denial of service due to maximum payload size sometimes not being enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48809"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-72766",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-843",
      "title": "n8n before 1.123.67 Arbitrary File Read via Send Email Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72766"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-61356",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-306",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61356"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-61364",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61364"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-61365",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61365"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-61367",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61367"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-63522",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-732",
      "title": "Azure SQL Database Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63522"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-44765",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Manufacturing Integration and Intelligence",
      "cwe": "CWE-862",
      "title": "Missing Authorization Check in SAP Manufacturing Integration and Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44765"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-62788",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62788"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-66809",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66809"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-66810",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66810"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-68809",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-459",
      "title": "Powerpoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68809"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-70310",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70310"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-70312",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Powerpoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70312"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-53414",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Clients",
      "cwe": "CWE-126",
      "title": "Zoom Clients - Buffer Over-read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53414"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-48046",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00273,
      "epss_percentile": 0.1977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-494",
      "title": "Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48046"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-73229",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "encode",
      "product": "django-rest-framework",
      "cwe": "CWE-200",
      "title": "Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73229"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-19519",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Security 4",
      "cwe": "CWE-617",
      "title": "Claircore: claircore: denial of service via unchecked type assertion in rpm header parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19519"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-71387",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-863",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71387"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-62776",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62776"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-72922",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-287",
      "title": "AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72922"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-68821",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "App Installer",
      "cwe": "CWE-269",
      "title": "Windows Package Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68821"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-18705",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-807",
      "title": "Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18705"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-18711",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18711"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-42142",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-862",
      "title": "TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42142"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-72598",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apioo",
      "product": "Fusio",
      "cwe": "CWE-918",
      "title": "Apioo Fusio - Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72598"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-21269",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.1925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-79",
      "title": "ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21269"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-62890",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows GDI+ Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62890"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-66799",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.1922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Key Guard Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66799"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-70307",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70307"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-18688",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-125",
      "title": "Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18688"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-18694",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-125",
      "title": "Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18694"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-65810",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft .NET Framework 3.5",
      "cwe": "CWE-23",
      "title": ".NET Framework Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65810"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-73085",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "advplyr",
      "product": "audiobookshelf",
      "cwe": "CWE-287",
      "title": "Audiobookshelf: Refresh Token Accepted on Resource Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73085"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-73087",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00267,
      "epss_percentile": 0.18999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amir20",
      "product": "dozzle",
      "cwe": "CWE-918",
      "title": "Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73087"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-50236",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.1889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4.19",
      "cwe": "CWE-918",
      "title": "Openshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50236"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-71383",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-863",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71383"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-72607",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koha Community",
      "product": "Koha",
      "cwe": "CWE-89",
      "title": "Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72607"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-66146",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "GMS",
      "cwe": "CWE-79",
      "title": "Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66146"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-15555",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-502",
      "title": "Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshaller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15555"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-72555",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Peppermint Lab",
      "product": "Peppermint",
      "cwe": "CWE-284",
      "title": "Peppermint Lab Peppermint - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72555"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-18639",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-290",
      "title": "Velociraptor OIDC Authenticator susceptible to email spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18639"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-18707",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Improper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18707"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-73157",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-79",
      "title": "cti-transmute Remote MISP Event Browser Allows Cross-Site Scripting via Malicious Event Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73157"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-58238",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-770",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58238"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-19078",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-601",
      "title": "Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing via unvalidated parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19078"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-18690",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18690"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-62775",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-863",
      "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62775"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-72747",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo Stored Cross-Site Scripting via Unauthenticated Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72747"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-29036",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaveGamble",
      "product": "cJSON",
      "cwe": "CWE-706",
      "title": "cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29036"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-62799",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-122",
      "title": "Windows SMB Client Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62799"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-65671",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Access API Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65671"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-65672",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Remote Access API Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65672"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-65774",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65774"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-18635",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-863",
      "title": "Velociraptor query plugin allows impersonation in other orgs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18635"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-48765",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.17317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-639",
      "title": "TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48765"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-62757",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-347",
      "title": "Windows Schannel Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62757"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-73140",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-862",
      "title": "cti-transmute Evaluation Report Exports Expose Private Comments and Author Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73140"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-73155",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-862",
      "title": "cti-transmute Missing Authorization Allows Reactions to Private Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73155"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-72769",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n before 1.123.67 Prototype Pollution via VM Expression Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72769"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-65814",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65814"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-48495",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.1676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-862",
      "title": "TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48495"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-62883",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62883"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-65795",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.1678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": null,
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65795"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-65797",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65797"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-65798",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.1678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65798"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-56720",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.1676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-862",
      "title": "CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56720"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-69117",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetBox Labs",
      "product": "NetBox",
      "cwe": "CWE-639",
      "title": "NetBox 4.5.8 ORM Injection via WritableNestedSerializer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69117"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-68792",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-77",
      "title": "Microsoft Office Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68792"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-63133",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cisagov",
      "product": "Malcolm",
      "cwe": "CWE-770",
      "title": "Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63133"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-63134",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cisagov",
      "product": "Malcolm",
      "cwe": "CWE-22",
      "title": "Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63134"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-73249",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "calibre",
      "cwe": "CWE-862",
      "title": "calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73249"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-73161",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-79",
      "title": "cti-transmute Conversion Table Allows XSS via Unescaped Cell Content During Search Highlighting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73161"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-11737",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RAX20",
      "cwe": "CWE-20",
      "title": "Some NETGEAR Nighthawk devices allow administrators to tamper with the device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11737"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-19558",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.1616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19558"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-50472",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50472"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-59125",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59125"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-61346",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61346"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-61361",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows DHCP Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61361"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-61366",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61366"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-61938",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61938"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-61939",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Winlogon Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61939"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-62723",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62723"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-62724",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62724"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-62726",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62726"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-73082",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activepieces",
      "product": "activepieces",
      "cwe": "CWE-200",
      "title": "Activepieces: Server-side request forgery in MCP tool validation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73082"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-73221",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cvat-ai",
      "product": "cvat",
      "cwe": "CWE-863",
      "title": "CVAT: Flawed authorization logic in endpoints related to lambda requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73221"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-18348",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-863",
      "title": "Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18348"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-20708",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "cwe": "CWE-532",
      "title": "Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20708"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-71384",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-863",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71384"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-65799",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65799"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-58230",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-601",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58230"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-66875",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-306",
      "title": "Mira Hormone Monitor, Mira Android App Missing authentication for critical function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66875"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-65773",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-284",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65773"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-48442",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-22",
      "title": "CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48442"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-48446",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-22",
      "title": "CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48446"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-67568",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-798",
      "title": "Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67568"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-62733",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62733"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-62736",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62736"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-62739",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62739"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-62755",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62755"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-62758",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.1533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62758"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-62770",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Shell Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62770"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-62771",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62771"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-62772",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-122",
      "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62772"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-62779",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Schannel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62779"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-62876",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62876"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-62877",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62877"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-62880",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62880"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-62885",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62885"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-62894",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62894"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-65786",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65786"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-65790",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65790"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-70345",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70345"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-72558",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CiviCRM",
      "product": "CiviCRM",
      "cwe": "CWE-89",
      "title": "CiviCRM CiviCRM - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72558"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-72562",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pimcore",
      "product": "pimcore admin-ui-classic-bundle",
      "cwe": "CWE-89",
      "title": "Pimcore pimcore admin-ui-classic-bundle - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72562"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-72921",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-863",
      "title": "SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72921"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-61349",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61349"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-69115",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIMSDK",
      "product": "OpenIM Server (open-im-server)",
      "cwe": "CWE-862",
      "title": "OpenIM Server v3.8.3 Missing Authorization on User and Group Enumeration Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69115"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-19579",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grokability",
      "product": "Snipe-IT",
      "cwe": "CWE-639",
      "title": "Snipe-IT Checkout Request Cancellation IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19579"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-66340",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-307",
      "title": "Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66340"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-18636",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-288",
      "title": "Velociraptor VFSGetBuffer API path deny list bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18636"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-44764",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Manufacturing Integration and Intelligence",
      "cwe": "CWE-862",
      "title": "Missing Authorization Check in SAP Manufacturing Integration and Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44764"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-70339",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-843",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70339"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-56179",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-346",
      "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56179"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-66778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-644",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66778"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-73158",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.1457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-20",
      "title": "cti-transmute Saved Graph Configuration Allows Stored Cross-Site Scripting via svgIcon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73158"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-73159",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-79",
      "title": "cti-transmute Stored XSS via Crafted Tag Icon on Admin Triage Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73159"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-72561",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Peppermint Lab",
      "product": "Peppermint",
      "cwe": "CWE-284",
      "title": "Peppermint Lab Peppermint - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72561"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-5304",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axis Communications AB",
      "product": "AXIS OS",
      "cwe": "CWE-1287",
      "title": "An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5304"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-18691",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00231,
      "epss_percentile": 0.14245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-757",
      "title": "Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18691"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-73084",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activepieces",
      "product": "activepieces",
      "cwe": "CWE-79",
      "title": "Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73084"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-18693",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-787",
      "title": "Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18693"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-72541",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Windmill Labs",
      "product": "Windmill",
      "cwe": "CWE-306",
      "title": "Windmill Labs Windmill - Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72541"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-72768",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n before 2.32.1 SSRF Protection Bypass via MCP Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72768"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-72542",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Windmill Labs",
      "product": "Windmill",
      "cwe": "CWE-306",
      "title": "Windmill Labs Windmill - Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72542"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-20765",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) TDX Guest software",
      "cwe": "CWE-697",
      "title": "Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20765"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-72780",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-294",
      "title": "Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72780"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-72782",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-668",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72782"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-19516",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00226,
      "epss_percentile": 0.13522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana MCP Server",
      "cwe": "CWE-918",
      "title": "CVE-2026-19516 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19516"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-65776",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65776"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-66832",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-598",
      "title": "Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66832"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-73090",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00224,
      "epss_percentile": 0.13296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chocobozzz",
      "product": "PeerTube",
      "cwe": "CWE-863",
      "title": "PeerTube: Cross-origin remote video takeover via Update activity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73090"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-72608",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koha Community",
      "product": "Koha",
      "cwe": "CWE-89",
      "title": "Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72608"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-48762",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-918",
      "title": "TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48762"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-69113",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CapSoftware",
      "product": "Cap",
      "cwe": "CWE-862",
      "title": "Cap v0.3.1 Broken Access Control via video comment endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69113"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-15554",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-295",
      "title": "Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15554"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-18634",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "GMS",
      "cwe": "CWE-502",
      "title": "An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18634"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-66774",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00221,
      "epss_percentile": 0.12973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-754",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66774"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-66761",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-770",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66761"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-58239",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-807",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58239"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-20878",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-476",
      "title": "Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20878"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-72609",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koha Community",
      "product": "Koha",
      "cwe": "CWE-89",
      "title": "Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72609"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-20886",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20886"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-72779",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-184",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72779"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-15556",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.1253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4.25",
      "cwe": "CWE-347",
      "title": "Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15556"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-8158",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axis Communications AB",
      "product": "Signed Video Framework",
      "cwe": null,
      "title": "The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8158"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-72772",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-640",
      "title": "n8n before 2.32.1 Authentication Bypass via Token Exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72772"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-72763",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.1221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 1.123.67 Credential Exfiltration via Sub-Workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72763"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-72771",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72771"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-66771",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAPUI5",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting (XSS) vulnerability in SAPUI5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66771"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-58237",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-862",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58237"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-42976",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42976"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-62777",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows License Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62777"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-65678",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65678"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-65778",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Autopilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65778"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-65779",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Autopilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65779"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-48443",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48443"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-48444",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-190",
      "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48444"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-48445",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-190",
      "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48445"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-58247",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP ABAP Platform",
      "cwe": "CWE-908",
      "title": "Memory Corruption vulnerability in SAP ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58247"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-19418",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-346",
      "title": "TYPO3 CMS - Broken Access Control in Backend and Install Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19418"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-18704",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-862",
      "title": "Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18704"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-72546",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.1169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Attendize",
      "product": "Attendize",
      "cwe": "CWE-639",
      "title": "Attendize Attendize - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72546"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-72547",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.1169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Attendize",
      "product": "Attendize",
      "cwe": "CWE-639",
      "title": "Attendize Attendize - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72547"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-72775",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n before 1.123.67 SQL Injection via PostgresTrigger Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72775"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-72750",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n before 1.123.67 SQL Injection via executeQuery Operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72750"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-72596",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ghost Foundation",
      "product": "Ghost",
      "cwe": "CWE-284",
      "title": "Ghost Foundation Ghost - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72596"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-61928",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-312",
      "title": "Windows Hello Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61928"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-48771",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ishankjha740",
      "product": "ishankportfolio",
      "cwe": "CWE-200",
      "title": "ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48771"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-18702",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-269",
      "title": "Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18702"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-50237",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.1119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4.19",
      "cwe": "CWE-918",
      "title": "Openshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via projecthelmchartrepository in openshift console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50237"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-71845",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-532",
      "title": "Insights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71845"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-72762",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-434",
      "title": "n8n before 1.123.67 Arbitrary File Write via Edit Image Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72762"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-72544",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "OpenSign",
      "cwe": "CWE-345",
      "title": "OpenSignLabs OpenSign - Insufficient Verification of Data Authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72544"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-73222",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davila7",
      "product": "claude-code-templates",
      "cwe": "CWE-78",
      "title": "Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73222"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-62780",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62780"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-72563",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BadChoice",
      "product": "Handesk",
      "cwe": "CWE-284",
      "title": "BadChoice Handesk - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72563"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-72595",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BadChoice",
      "product": "Handesk",
      "cwe": "CWE-284",
      "title": "BadChoice Handesk - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72595"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-72560",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HumanSignal",
      "product": "Label Studio",
      "cwe": "CWE-918",
      "title": "HumanSignal Label Studio - Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72560"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-72597",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Friendica",
      "product": "Friendica",
      "cwe": "CWE-918",
      "title": "Friendica Friendica - Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72597"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-66779",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver Application Server ABAP",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66779"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-66149",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "Email Security",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66149"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-66150",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "Email Security",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66150"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-62725",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62725"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-62749",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.1011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62749"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-62753",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62753"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-62773",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Kerberos Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62773"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-62774",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.1011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62774"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-62892",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62892"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-65780",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.1011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-415",
      "title": "Windows Autopilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65780"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-65781",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.1011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Autopilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65781"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-65782",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Autopilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65782"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-65783",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Autopilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65783"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-19517",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-770",
      "title": "Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19517"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-19518",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-1284",
      "title": "Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19518"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-71474",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-532",
      "title": "Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71474"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-72610",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koha Community",
      "product": "Koha",
      "cwe": "CWE-89",
      "title": "Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72610"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-66098",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-306",
      "title": "Mira Hormone Monitor, Mira Android App Missing authentication for critical function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66098"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-11738",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "R7000",
      "cwe": "CWE-20",
      "title": "Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11738"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-47702",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00196,
      "epss_percentile": 0.09699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-312",
      "title": "TypeBot API tokens stored in plaintext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47702"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-72785",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00194,
      "epss_percentile": 0.09497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-863",
      "title": "Craft CMS before 5.10.6 Authorization Bypass via structures/move-element",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72785"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-73245",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-306",
      "title": "Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73245"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-72925",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "swc-project",
      "product": "swc",
      "cwe": "CWE-79",
      "title": "SWC HTML minifier may allow script element breakout when minifying embedded JSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72925"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-66773",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "Odata",
      "cwe": "CWE-601",
      "title": "Server-controlled `__next` URL is not checking cross-origin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66773"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2026-48441",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-22",
      "title": "Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48441"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2026-19550",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-863",
      "title": "Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19550"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2026-34635",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.0913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-321",
      "title": "ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34635"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-71468",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-266",
      "title": "Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71468"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-59122",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59122"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-59126",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-362",
      "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59126"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-61927",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61927"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-62690",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62690"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-62693",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-362",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62693"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-62705",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-362",
      "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62705"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-62728",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-367",
      "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62728"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-62729",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62729"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-62734",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62734"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-62748",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62748"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-71290",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00187,
      "epss_percentile": 0.08649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HttpComponents Client",
      "cwe": "CWE-295",
      "title": "Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71290"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-12052",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12052"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-73068",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-639",
      "title": "ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73068"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-64934",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.0823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-807",
      "title": "Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64934"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-66772",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP BusinessObjects Business Intelligence Platform (Admin Tools)",
      "cwe": "CWE-862",
      "title": "Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66772"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-47940",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-190",
      "title": "Lightroom Classic | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47940"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-63177",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cisagov",
      "product": "Malcolm",
      "cwe": "CWE-863",
      "title": "Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63177"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-18712",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18712"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-24911",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24911"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-14548",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.0723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ray Enterprise Translation",
      "cwe": "CWE-862",
      "title": "Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14548"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-58235",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver AS Java (Adobe Document Services)",
      "cwe": "CWE-1395",
      "title": "Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58235"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-73162",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "cti-transmute",
      "cwe": "CWE-352",
      "title": "cti-transmute CSRF Allows Unauthorized Follow and Notification State Changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73162"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-20727",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-476",
      "title": "Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20727"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-20776",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software",
      "cwe": "CWE-754",
      "title": "Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20776"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-22887",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-119",
      "title": "Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22887"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-20749",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow an escalation of privilege. Network adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20749"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-20739",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-754",
      "title": "Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20739"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-20745",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20745"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-20747",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software",
      "cwe": "CWE-754",
      "title": "Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20747"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-20787",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-476",
      "title": "Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20787"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-20795",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-119",
      "title": "Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20795"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-58245",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00172,
      "epss_percentile": 0.0695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Advanced Planning and Optimization (Model Mix Planning)",
      "cwe": "CWE-798",
      "title": "Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58245"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-53416",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom VDI",
      "cwe": "CWE-23",
      "title": "Zoom VDI - Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53416"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-11894",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-415",
      "title": "Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11894"
    },
    {
      "rank": 778,
      "cve_id": "CVE-2026-25194",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.0017,
      "epss_percentile": 0.06772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25194"
    },
    {
      "rank": 779,
      "cve_id": "CVE-2026-67558",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanovate Tech Inc. (operating as Mira / Mira Care)",
      "product": "Mira Firmware",
      "cwe": "CWE-290",
      "title": "Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67558"
    },
    {
      "rank": 780,
      "cve_id": "CVE-2026-18687",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-191",
      "title": "Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index Corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18687"
    },
    {
      "rank": 781,
      "cve_id": "CVE-2026-5303",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axis Communications AB",
      "product": "AXIS OS",
      "cwe": "CWE-367",
      "title": "The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5303"
    },
    {
      "rank": 782,
      "cve_id": "CVE-2026-18698",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18698"
    },
    {
      "rank": 783,
      "cve_id": "CVE-2026-58244",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Manufacturing Integration and Intelligence",
      "cwe": "CWE-862",
      "title": "Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58244"
    },
    {
      "rank": 784,
      "cve_id": "CVE-2026-66764",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP S/4 HANA (Reprocess Bank Statement Items)",
      "cwe": "CWE-639",
      "title": "Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66764"
    },
    {
      "rank": 785,
      "cve_id": "CVE-2026-12051",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in USB DFU device_next download handler (handle_download)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12051"
    },
    {
      "rank": 786,
      "cve_id": "CVE-2026-67180",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Turbinia",
      "cwe": "CWE-78",
      "title": "Google Turbinia arbitrary command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67180"
    },
    {
      "rank": 787,
      "cve_id": "CVE-2026-48387",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-190",
      "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48387"
    },
    {
      "rank": 788,
      "cve_id": "CVE-2026-48434",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48434"
    },
    {
      "rank": 789,
      "cve_id": "CVE-2026-48435",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-191",
      "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48435"
    },
    {
      "rank": 790,
      "cve_id": "CVE-2026-32677",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "gaudi-container-runtime",
      "cwe": "CWE-22",
      "title": "Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32677"
    },
    {
      "rank": 791,
      "cve_id": "CVE-2026-59693",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Desigo DXR2",
      "cwe": "CWE-754",
      "title": "A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59693"
    },
    {
      "rank": 792,
      "cve_id": "CVE-2026-73282",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-416",
      "title": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73282"
    },
    {
      "rank": 793,
      "cve_id": "CVE-2026-9214",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "R7000",
      "cwe": "CWE-20",
      "title": "Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9214"
    },
    {
      "rank": 794,
      "cve_id": "CVE-2026-6726",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Computing Group",
      "product": "TPM2.0",
      "cwe": "CWE-704",
      "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6726"
    },
    {
      "rank": 795,
      "cve_id": "CVE-2026-72553",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ElkArte Forum",
      "product": "ElkArte",
      "cwe": "CWE-79",
      "title": "ElkArte Forum ElkArte - Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72553"
    },
    {
      "rank": 796,
      "cve_id": "CVE-2026-48404",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-787",
      "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48404"
    },
    {
      "rank": 797,
      "cve_id": "CVE-2026-48405",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-787",
      "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48405"
    },
    {
      "rank": 798,
      "cve_id": "CVE-2026-48406",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-787",
      "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48406"
    },
    {
      "rank": 799,
      "cve_id": "CVE-2026-48407",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-787",
      "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48407"
    },
    {
      "rank": 800,
      "cve_id": "CVE-2026-48408",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-787",
      "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48408"
    },
    {
      "rank": 801,
      "cve_id": "CVE-2026-48409",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-787",
      "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48409"
    },
    {
      "rank": 802,
      "cve_id": "CVE-2026-48410",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-787",
      "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48410"
    },
    {
      "rank": 803,
      "cve_id": "CVE-2026-73234",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeCAD",
      "product": "FreeCAD",
      "cwe": "CWE-22",
      "title": "FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73234"
    },
    {
      "rank": 804,
      "cve_id": "CVE-2026-20891",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-287",
      "title": "Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20891"
    },
    {
      "rank": 805,
      "cve_id": "CVE-2026-11893",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-415",
      "title": "Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11893"
    },
    {
      "rank": 806,
      "cve_id": "CVE-2026-58241",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard",
      "cwe": "CWE-862",
      "title": "Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58241"
    },
    {
      "rank": 807,
      "cve_id": "CVE-2026-73281",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00158,
      "epss_percentile": 0.05497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-669",
      "title": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73281"
    },
    {
      "rank": 808,
      "cve_id": "CVE-2026-66770",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.0538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Social Intelligence",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in SAP Social Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66770"
    },
    {
      "rank": 809,
      "cve_id": "CVE-2026-73083",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activepieces",
      "product": "activepieces",
      "cwe": "CWE-693",
      "title": "Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73083"
    },
    {
      "rank": 810,
      "cve_id": "CVE-2026-16974",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-79",
      "title": "Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16974"
    },
    {
      "rank": 811,
      "cve_id": "CVE-2026-71390",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71390"
    },
    {
      "rank": 812,
      "cve_id": "CVE-2026-73231",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faker-js",
      "product": "faker",
      "cwe": "CWE-95",
      "title": "Faker: helpers.fake exploitable into arbritary code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73231"
    },
    {
      "rank": 813,
      "cve_id": "CVE-2026-20903",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) AI Containers",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20903"
    },
    {
      "rank": 814,
      "cve_id": "CVE-2026-20906",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Neural Compressor software",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20906"
    },
    {
      "rank": 815,
      "cve_id": "CVE-2026-21387",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) LLM Library for PyTorch",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21387"
    },
    {
      "rank": 816,
      "cve_id": "CVE-2026-21400",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) AI Reference Models",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21400"
    },
    {
      "rank": 817,
      "cve_id": "CVE-2026-28700",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "EquiTriton",
      "cwe": "CWE-427",
      "title": "Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28700"
    },
    {
      "rank": 818,
      "cve_id": "CVE-2026-32788",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Approximate Bayesian Inference Framework",
      "cwe": "CWE-427",
      "title": "Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32788"
    },
    {
      "rank": 819,
      "cve_id": "CVE-2026-34175",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Hardware-Aware-Automated-MachineLearning NA",
      "cwe": "CWE-427",
      "title": "Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34175"
    },
    {
      "rank": 820,
      "cve_id": "CVE-2026-62908",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62908"
    },
    {
      "rank": 821,
      "cve_id": "CVE-2026-71389",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-191",
      "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71389"
    },
    {
      "rank": 822,
      "cve_id": "CVE-2026-6727",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trusted Computing Group",
      "product": "TPM2.0",
      "cwe": "CWE-208",
      "title": "CVE-2026-6727",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6727"
    },
    {
      "rank": 823,
      "cve_id": "CVE-2026-14549",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ray Enterprise Translation",
      "cwe": "CWE-862",
      "title": "Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14549"
    },
    {
      "rank": 824,
      "cve_id": "CVE-2026-19391",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Pen Drive Powered by Red Hat Lightspeed",
      "cwe": "CWE-312",
      "title": "Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19391"
    },
    {
      "rank": 825,
      "cve_id": "CVE-2026-73233",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeCAD",
      "product": "FreeCAD",
      "cwe": "CWE-94",
      "title": "FreeCAD: FEM formula incomplete escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73233"
    },
    {
      "rank": 826,
      "cve_id": "CVE-2026-73248",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "calibre",
      "cwe": "CWE-94",
      "title": "calibre: Bypass of Python template restrictions via nested `template()` leading to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73248"
    },
    {
      "rank": 827,
      "cve_id": "CVE-2026-20778",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20778"
    },
    {
      "rank": 828,
      "cve_id": "CVE-2026-20885",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) platforms",
      "cwe": "CWE-287",
      "title": "Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20885"
    },
    {
      "rank": 829,
      "cve_id": "CVE-2026-72783",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-22",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72783"
    },
    {
      "rank": 830,
      "cve_id": "CVE-2025-48506",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows",
      "cwe": "CWE-427",
      "title": "Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48506"
    },
    {
      "rank": 831,
      "cve_id": "CVE-2026-25652",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.0447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-863",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25652"
    },
    {
      "rank": 832,
      "cve_id": "CVE-2026-72784",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-918",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72784"
    },
    {
      "rank": 833,
      "cve_id": "CVE-2026-48447",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Lightroom Classic",
      "cwe": "CWE-863",
      "title": "Lightroom Classic | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48447"
    },
    {
      "rank": 834,
      "cve_id": "CVE-2026-20769",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) NPU Driver",
      "cwe": "CWE-754",
      "title": "Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20769"
    },
    {
      "rank": 835,
      "cve_id": "CVE-2026-20786",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) NPU Driver",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20786"
    },
    {
      "rank": 836,
      "cve_id": "CVE-2026-20752",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software",
      "cwe": "CWE-287",
      "title": "Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20752"
    },
    {
      "rank": 837,
      "cve_id": "CVE-2026-44762",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Data Services Management Console",
      "cwe": "CWE-1021",
      "title": "Security Misconfiguration in SAP Data Services Management Console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44762"
    },
    {
      "rank": 838,
      "cve_id": "CVE-2026-18709",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-862",
      "title": "Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18709"
    },
    {
      "rank": 839,
      "cve_id": "CVE-2026-73077",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-78",
      "title": "Vim: Arbitrary Code Execution via Shell Keyword Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73077"
    },
    {
      "rank": 840,
      "cve_id": "CVE-2026-66776",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-347",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66776"
    },
    {
      "rank": 841,
      "cve_id": "CVE-2025-0041",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "Vitis™ Embedded Single File Download (SFD) for Windows",
      "cwe": "CWE-427",
      "title": "Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-0041"
    },
    {
      "rank": 842,
      "cve_id": "CVE-2026-67179",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "genkit-ai",
      "product": "genkit",
      "cwe": "CWE-644",
      "title": "Genkit improper host header validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67179"
    },
    {
      "rank": 843,
      "cve_id": "CVE-2026-72744",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-200",
      "title": "Nuxt before 4.5.1 Information Disclosure via Chrome DevTools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72744"
    },
    {
      "rank": 844,
      "cve_id": "CVE-2026-20737",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-200",
      "title": "Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20737"
    },
    {
      "rank": 845,
      "cve_id": "CVE-2026-73036",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.0333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bash-it",
      "product": "Bash-it",
      "cwe": "CWE-150",
      "title": "Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73036"
    },
    {
      "rank": 846,
      "cve_id": "CVE-2026-18844",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pulsetto",
      "product": "Vagus Nerve Stimulator",
      "cwe": "CWE-912",
      "title": "Pulsetto Vagus Nerve Stimulator Hidden Functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18844"
    },
    {
      "rank": 847,
      "cve_id": "CVE-2026-72559",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.0328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daniel Brendel",
      "product": "HortusFox",
      "cwe": "CWE-79",
      "title": "Daniel Brendel HortusFox - Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72559"
    },
    {
      "rank": 848,
      "cve_id": "CVE-2026-33921",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Arc",
      "cwe": "CWE-1188",
      "title": "Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33921"
    },
    {
      "rank": 849,
      "cve_id": "CVE-2026-24099",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-416",
      "title": "Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. System software adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24099"
    },
    {
      "rank": 850,
      "cve_id": "CVE-2026-73076",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73076"
    },
    {
      "rank": 851,
      "cve_id": "CVE-2026-66763",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP BusinessObjects Business Intelligence Platform (Central Management Server)",
      "cwe": "CWE-321",
      "title": "Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66763"
    },
    {
      "rank": 852,
      "cve_id": "CVE-2026-66154",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "GMS",
      "cwe": "CWE-295",
      "title": "An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66154"
    },
    {
      "rank": 853,
      "cve_id": "CVE-2026-20780",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-400",
      "title": "Uncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20780"
    },
    {
      "rank": 854,
      "cve_id": "CVE-2026-73250",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-77",
      "title": "Notepad++: Install-time PowerShell command injection through installation path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73250"
    },
    {
      "rank": 855,
      "cve_id": "CVE-2026-73230",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ente",
      "product": "ente",
      "cwe": "CWE-200",
      "title": "Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73230"
    },
    {
      "rank": 856,
      "cve_id": "CVE-2026-72694",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-59",
      "title": "Mrtg: mrtg daemon symlink-following chown allows local privilege escalation via pid file path manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72694"
    },
    {
      "rank": 857,
      "cve_id": "CVE-2026-20789",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-284",
      "title": "Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20789"
    },
    {
      "rank": 858,
      "cve_id": "CVE-2026-73066",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-787",
      "title": "Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73066"
    },
    {
      "rank": 859,
      "cve_id": "CVE-2026-73067",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-125",
      "title": "Tesseract: Heap OOB read in the DAWG loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73067"
    },
    {
      "rank": 860,
      "cve_id": "CVE-2026-73072",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-122",
      "title": "Vim: Heap Buffer Overflow when Loading a Spell File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73072"
    },
    {
      "rank": 861,
      "cve_id": "CVE-2026-73235",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeCAD",
      "product": "FreeCAD",
      "cwe": "CWE-611",
      "title": "FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73235"
    },
    {
      "rank": 862,
      "cve_id": "CVE-2026-20890",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software for Windows",
      "cwe": "CWE-269",
      "title": "Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20890"
    },
    {
      "rank": 863,
      "cve_id": "CVE-2026-33922",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Arc",
      "cwe": "CWE-22",
      "title": "Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33922"
    },
    {
      "rank": 864,
      "cve_id": "CVE-2026-66775",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.0259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-352",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66775"
    },
    {
      "rank": 865,
      "cve_id": "CVE-2026-20741",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) PROSet/Wireless WiFi Software",
      "cwe": "CWE-284",
      "title": "Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (low) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20741"
    },
    {
      "rank": 866,
      "cve_id": "CVE-2026-66760",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.0213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business AI Platform (Approuter)",
      "cwe": "CWE-295",
      "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66760"
    },
    {
      "rank": 867,
      "cve_id": "CVE-2026-20734",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "cwe": "CWE-665",
      "title": "Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20734"
    },
    {
      "rank": 868,
      "cve_id": "CVE-2026-20728",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel Extension for TensorFlow software",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20728"
    },
    {
      "rank": 869,
      "cve_id": "CVE-2026-20755",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "LLM Scaler software",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20755"
    },
    {
      "rank": 870,
      "cve_id": "CVE-2026-20770",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Cluster Management Toolkit for Kubernetes software",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20770"
    },
    {
      "rank": 871,
      "cve_id": "CVE-2026-24693",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) oneCCL Bindings for PyTorch",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24693"
    },
    {
      "rank": 872,
      "cve_id": "CVE-2026-28707",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "LLM-on-Ray",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28707"
    },
    {
      "rank": 873,
      "cve_id": "CVE-2026-28757",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Workload Services Framework software",
      "cwe": "CWE-693",
      "title": "Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28757"
    },
    {
      "rank": 874,
      "cve_id": "CVE-2026-20712",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) reference platforms",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20712"
    },
    {
      "rank": 875,
      "cve_id": "CVE-2026-43606",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "Vitis™  Libraries - Security Module",
      "cwe": "CWE-208",
      "title": "Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43606"
    },
    {
      "rank": 876,
      "cve_id": "CVE-2026-17535",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-125",
      "title": "Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17535"
    },
    {
      "rank": 877,
      "cve_id": "CVE-2026-20898",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.",
      "cwe": "CWE-284",
      "title": "Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20898"
    },
    {
      "rank": 878,
      "cve_id": "CVE-2025-8087",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Power Design Manager (PDM) Software Un-Installer",
      "cwe": "CWE-427",
      "title": "A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8087"
    },
    {
      "rank": 879,
      "cve_id": "CVE-2025-54512",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Ryzen™ Master",
      "cwe": "CWE-427",
      "title": "A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54512"
    },
    {
      "rank": 880,
      "cve_id": "CVE-2026-73075",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-124",
      "title": "Vim: Out-of-bounds Access in Popup Opacity Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73075"
    },
    {
      "rank": 881,
      "cve_id": "CVE-2026-32791",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Performance Counter Monitor (Intel(R) PCM)",
      "cwe": "CWE-426",
      "title": "Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32791"
    },
    {
      "rank": 882,
      "cve_id": "CVE-2026-59086",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Simcenter Femap",
      "cwe": "CWE-121",
      "title": "A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59086"
    },
    {
      "rank": 883,
      "cve_id": "CVE-2026-18703",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00115,
      "epss_percentile": 0.01811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication Method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18703"
    },
    {
      "rank": 884,
      "cve_id": "CVE-2026-8917",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "GPU Tweak III",
      "cwe": "CWE-822",
      "title": "Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the ' Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8917"
    },
    {
      "rank": 885,
      "cve_id": "CVE-2026-21399",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R)",
      "cwe": "CWE-122",
      "title": "Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0.2 within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21399"
    },
    {
      "rank": 886,
      "cve_id": "CVE-2026-0465",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Ryzen™ Master",
      "cwe": "CWE-416",
      "title": "A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0465"
    },
    {
      "rank": 887,
      "cve_id": "CVE-2026-18710",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Driver",
      "cwe": "CWE-532",
      "title": "Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18710"
    },
    {
      "rank": 888,
      "cve_id": "CVE-2026-50058",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Solid Edge SE2025",
      "cwe": "CWE-125",
      "title": "A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50058"
    },
    {
      "rank": 889,
      "cve_id": "CVE-2026-50059",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Solid Edge SE2025",
      "cwe": "CWE-787",
      "title": "A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50059"
    },
    {
      "rank": 890,
      "cve_id": "CVE-2026-50060",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Solid Edge SE2025",
      "cwe": "CWE-416",
      "title": "A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50060"
    },
    {
      "rank": 891,
      "cve_id": "CVE-2026-50061",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Solid Edge SE2025",
      "cwe": "CWE-416",
      "title": "A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50061"
    },
    {
      "rank": 892,
      "cve_id": "CVE-2026-50062",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Solid Edge SE2025",
      "cwe": "CWE-125",
      "title": "A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50062"
    },
    {
      "rank": 893,
      "cve_id": "CVE-2026-50063",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Solid Edge SE2025",
      "cwe": "CWE-125",
      "title": "A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50063"
    },
    {
      "rank": 894,
      "cve_id": "CVE-2026-50064",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Solid Edge SE2025",
      "cwe": "CWE-787",
      "title": "A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50064"
    },
    {
      "rank": 895,
      "cve_id": "CVE-2026-59700",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Simcenter Femap",
      "cwe": "CWE-125",
      "title": "A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59700"
    },
    {
      "rank": 896,
      "cve_id": "CVE-2026-59701",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Simcenter Femap",
      "cwe": "CWE-125",
      "title": "A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59701"
    },
    {
      "rank": 897,
      "cve_id": "CVE-2026-64629",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Parasolid V38.0",
      "cwe": "CWE-125",
      "title": "A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64629"
    },
    {
      "rank": 898,
      "cve_id": "CVE-2025-48505",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows",
      "cwe": "CWE-276",
      "title": "Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged escalation, potentially resulting in arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48505"
    },
    {
      "rank": 899,
      "cve_id": "CVE-2026-69108",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Siemens License Server (SLS)",
      "cwe": "CWE-732",
      "title": "A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69108"
    },
    {
      "rank": 900,
      "cve_id": "CVE-2026-57262",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.0156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "LOGO! Soft Comfort",
      "cwe": "CWE-321",
      "title": "A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57262"
    },
    {
      "rank": 901,
      "cve_id": "CVE-2026-20731",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) NPU Driver",
      "cwe": "CWE-119",
      "title": "Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20731"
    },
    {
      "rank": 902,
      "cve_id": "CVE-2026-20783",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) NPU Driver",
      "cwe": "CWE-754",
      "title": "Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20783"
    },
    {
      "rank": 903,
      "cve_id": "CVE-2026-27765",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.0157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vLLM Hardware Plugin for Intel(R) Gaudi(R) software",
      "cwe": "CWE-20",
      "title": "Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27765"
    },
    {
      "rank": 904,
      "cve_id": "CVE-2026-20913",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Neural Compressor software",
      "cwe": "CWE-20",
      "title": "Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20913"
    },
    {
      "rank": 905,
      "cve_id": "CVE-2026-20763",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) TDX Guest software",
      "cwe": "CWE-682",
      "title": "Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20763"
    },
    {
      "rank": 906,
      "cve_id": "CVE-2026-28729",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts.",
      "cwe": "CWE-190",
      "title": "Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28729"
    },
    {
      "rank": 907,
      "cve_id": "CVE-2026-73070",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-121",
      "title": "Vim: Stack Buffer Overflow in the Vim Socket Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73070"
    },
    {
      "rank": 908,
      "cve_id": "CVE-2026-20917",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Processors",
      "cwe": "CWE-1422",
      "title": "Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20917"
    },
    {
      "rank": 909,
      "cve_id": "CVE-2026-73071",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00109,
      "epss_percentile": 0.0144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-416",
      "title": "Vim: Use-after-free in JSON Decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73071"
    },
    {
      "rank": 910,
      "cve_id": "CVE-2026-73074",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.0136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-190",
      "title": "Vim: Heap Buffer Overflow in Text Property Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73074"
    },
    {
      "rank": 911,
      "cve_id": "CVE-2025-0046",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Power Design Manager (PDM) Software Installer for Windows",
      "cwe": "CWE-732",
      "title": "Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-0046"
    },
    {
      "rank": 912,
      "cve_id": "CVE-2026-72693",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-284",
      "title": "Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72693"
    },
    {
      "rank": 913,
      "cve_id": "CVE-2026-48790",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tursodatabase",
      "product": "turso-cli",
      "cwe": "CWE-276",
      "title": "turso-cli persists Turso platform JWT with world-readable (0o644) file permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48790"
    },
    {
      "rank": 914,
      "cve_id": "CVE-2026-20760",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Processors",
      "cwe": "CWE-1260",
      "title": "Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20760"
    },
    {
      "rank": 915,
      "cve_id": "CVE-2026-48437",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-295",
      "title": "CAI Content Credentials | Improper Certificate Validation (CWE-295)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48437"
    },
    {
      "rank": 916,
      "cve_id": "CVE-2025-61970",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "Vitis™ Embedded Single File Download (SFD) for Windows",
      "cwe": "CWE-276",
      "title": "Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61970"
    },
    {
      "rank": 917,
      "cve_id": "CVE-2026-20705",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) platform",
      "cwe": "CWE-922",
      "title": "Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20705"
    },
    {
      "rank": 918,
      "cve_id": "CVE-2026-20775",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) TDX modules",
      "cwe": "CWE-248",
      "title": "Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20775"
    },
    {
      "rank": 919,
      "cve_id": "CVE-2025-35973",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Processors",
      "cwe": "CWE-229",
      "title": "Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-35973"
    },
    {
      "rank": 920,
      "cve_id": "CVE-2026-20713",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.",
      "cwe": "CWE-670",
      "title": "Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20713"
    },
    {
      "rank": 921,
      "cve_id": "CVE-2025-35987",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Software Guard Extensions Data Center Attestation Primitives",
      "cwe": "CWE-223",
      "title": "Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (low) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-35987"
    },
    {
      "rank": 922,
      "cve_id": "CVE-2026-20901",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.0104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Xeon(R) processors",
      "cwe": "CWE-20",
      "title": "Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20901"
    },
    {
      "rank": 923,
      "cve_id": "CVE-2025-31936",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00096,
      "epss_percentile": 0.0083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Xeon(R) 6 processors when using Intel(R) TDX",
      "cwe": "CWE-1260",
      "title": "Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31936"
    },
    {
      "rank": 924,
      "cve_id": "CVE-2026-20799",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Battery Life Diagnostic Tool software",
      "cwe": "CWE-426",
      "title": "Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20799"
    },
    {
      "rank": 925,
      "cve_id": "CVE-2026-11985",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00092,
      "epss_percentile": 0.00584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-200",
      "title": "Cross-thread FPU register leak on ARM when FPU enabled without register sharing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11985"
    },
    {
      "rank": 926,
      "cve_id": "CVE-2026-20716",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00087,
      "epss_percentile": 0.00429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Processors",
      "cwe": "CWE-284",
      "title": "Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20716"
    },
    {
      "rank": 927,
      "cve_id": "CVE-2025-31938",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "cwe": "CWE-1220",
      "title": "Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31938"
    },
    {
      "rank": 928,
      "cve_id": "CVE-2026-57263",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00084,
      "epss_percentile": 0.00325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "LOGO! Soft Comfort",
      "cwe": "CWE-759",
      "title": "A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57263"
    },
    {
      "rank": 929,
      "cve_id": "CVE-2026-73283",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00083,
      "epss_percentile": 0.00282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-670",
      "title": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73283"
    },
    {
      "rank": 930,
      "cve_id": "CVE-2026-20707",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00077,
      "epss_percentile": 0.00132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "3rd Gen Intel(R) Xeon(R) Scalable Processors",
      "cwe": "CWE-1298",
      "title": "Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20707"
    },
    {
      "rank": 931,
      "cve_id": "CVE-2026-6505",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00074,
      "epss_percentile": 0.00084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axis Communications AB",
      "product": "AXIS OS",
      "cwe": "CWE-367",
      "title": "The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6505"
    },
    {
      "rank": 932,
      "cve_id": "CVE-2026-20908",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00073,
      "epss_percentile": 0.00078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) NPU Driver for Windows",
      "cwe": "CWE-367",
      "title": "Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20908"
    },
    {
      "rank": 933,
      "cve_id": "CVE-2025-31356",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00072,
      "epss_percentile": 0.00058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Intel(R) Trust Domain Extensions (Intel(R) TDX)",
      "cwe": "CWE-345",
      "title": "Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31356"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-0296",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-0296 (Cisco Adaptive Security Appliance (ASA)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-2725",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-2725 (Oracle Corporation Tape Library ACSLS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-3452",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-3452 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-44228",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-44228 (Apache Log4j2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-44487 (IETF HTTP/2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-20353",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-20353 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-20359",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-20359 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-23692",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-23692 (Rejetto HTTP File Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-42999",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-42999 (SAP_SE SAP NetWeaver (Visual Composer development server)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12971",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12971 (Unknown LearnPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13170",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13170 (Unknown Eventin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13600",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13600 (Unknown AutoNetTV Relay). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13716",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13716 (Arcadia Technology, LLC Crafty Controller). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14211",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14211 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14237",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14237 (Unknown vitepos). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14238",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14238 (Unknown vitepos). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14293 (Unknown Autopay). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14315",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14315 (Unknown Pixel Tag Manager for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14860",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14860 (Unknown Podcast Player). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14941",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14941 (Unknown Customer Reviews for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15047",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15047 (Unknown s2Member). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15229",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15229 (Unknown Pinpoint Booking System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15237",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15237 (Unknown MotoPress Hotel Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15238",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15238 (Unknown MotoPress Hotel Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16257",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16257 (Unknown Arvow AI SEO Writer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16298",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16298 (Unknown FoodBoxBooker). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16299",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16299 (Unknown Single Sign On For TNG). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16949",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16949 (Unknown Term Pages). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16985",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16985 (Unknown Squeeze). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17012 (Unknown Accept PayPal & Stripe with Subscriptions for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17016 (Unknown Accept PayPal & Stripe with Subscriptions for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17018",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17018 (Unknown CubeWP Framework). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17020",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17020 (Unknown Salon Booking System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17021",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17021 (Unknown Salon Booking System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17023",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17023 (Unknown Salon Booking System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17540",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17540 (Unknown File Manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18030",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18030 (Unknown BricksForge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18200",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18200 (Unknown FoodBoxBooker). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18468",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18468 (Unknown Login & Register Forms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18469",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18469 (Unknown Login & Register Forms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18666",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18666 (Unknown Library Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18786",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18786 (Unknown CheckView). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18934",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18934 (Unknown RSS Aggregator by Feedzy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18960",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18960 (Unknown Block User Account). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19049 (Unknown ProSolution WP Client). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19074",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19074 (Unknown Advanced Classifieds & Directory Pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19075",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19075 (Unknown All-in-One Video Gallery). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19077",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19077 (Unknown Duplicate Post). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19089",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19089 (Unknown Product Input Fields for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19379",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19379 (EFM ipTIME AX8004M). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19384",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19384 (SourceCodester Simple Doctors Appointment System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25646",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25646 (pnggroup libpng). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48939 (icagenda.com iCagenda extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69112",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69112 (huggingface accelerate). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69114",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69114 (Spacebar Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69116",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69116 (xpf0000 FlyEnv). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69118",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69118 (cachethq cachet). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70622",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70622 (composefs tar-rs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71964",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71964 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71965",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71965 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73030",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73030 (frostming unearth). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73033 (sucuri-wordpress-plugin). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-68686",
      "detail": "DUE DATE PASSED — CVE-2025-68686 (Fortinet FortiOS). CISA remediation deadline was August 10, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-8037",
      "detail": "DUE DATE PASSED — CVE-2026-8037 (Progress Software LoadMaster). CISA remediation deadline was August 10, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-21198",
      "detail": "RESCORED — CVE-2022-21198 (Intel(R) Processors). CVSS 7.9 → 6.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-20269",
      "detail": "RESCORED — CVE-2023-20269 (Cisco Adaptive Security Appliance (ASA) Software). CVSS 5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-9341",
      "detail": "RESCORED — CVE-2024-9341 (github.com/containers/common). CVSS 5.4 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-43892",
      "detail": "RESCORED — CVE-2025-43892 (Fortinet FortiOS). CVSS 4.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-62675",
      "detail": "RESCORED — CVE-2025-62675 (Fortinet FortiOS). CVSS 3.4 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-62826",
      "detail": "RESCORED — CVE-2025-62826 (Fortinet FortiPAM). CVSS 3.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-13473",
      "detail": "RESCORED — CVE-2026-13473 (IBM Storage Protect Client). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-14501",
      "detail": "RESCORED — CVE-2026-14501 (IBM Db2 Genius Hub). CVSS 4.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-14615",
      "detail": "RESCORED — CVE-2026-14615 (Red Hat build of Keycloak 26.4). CVSS 4.3 → 2.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-14971",
      "detail": "RESCORED — CVE-2026-14971 (IBM PowerVM Novalink). CVSS 3.9 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-14979",
      "detail": "RESCORED — CVE-2026-14979 (IBM Engineering Lifecycle Management). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-15995",
      "detail": "RESCORED — CVE-2026-15995 (IBM Cognos Analytics). CVSS 5.4 → 4.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-43003",
      "detail": "RESCORED — CVE-2026-43003 (OpenStack ironic-python-agent). CVSS 8 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58016",
      "detail": "RESCORED — CVE-2026-58016 (GNOME GLib). CVSS 7.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59837",
      "detail": "RESCORED — CVE-2026-59837 (Fortinet FortiPAM). CVSS 5.9 → 6.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59839",
      "detail": "RESCORED — CVE-2026-59839 (Fortinet FortiProxy). CVSS 5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59840",
      "detail": "RESCORED — CVE-2026-59840 (Fortinet FortiOS). CVSS 4.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-9698",
      "detail": "RESCORED — CVE-2026-9698 (HMBRAND DBI). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2018-0296",
      "detail": "ENRICHED — CVE-2018-0296 (Cisco Adaptive Security Appliance (ASA)). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-27339",
      "detail": "ENRICHED — CVE-2020-27339. Received CVSS 6.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-3452",
      "detail": "ENRICHED — CVE-2020-3452 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-3580",
      "detail": "ENRICHED — CVE-2020-3580 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 6.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-5953",
      "detail": "ENRICHED — CVE-2020-5953. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-33625",
      "detail": "ENRICHED — CVE-2021-33625. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-33626",
      "detail": "ENRICHED — CVE-2021-33626. Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-33627",
      "detail": "ENRICHED — CVE-2021-33627. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-41837",
      "detail": "ENRICHED — CVE-2021-41837. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-41838",
      "detail": "ENRICHED — CVE-2021-41838. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-41839",
      "detail": "ENRICHED — CVE-2021-41839. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-41840",
      "detail": "ENRICHED — CVE-2021-41840. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-41841",
      "detail": "ENRICHED — CVE-2021-41841. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-42059",
      "detail": "ENRICHED — CVE-2021-42059. Received CVSS 6.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-42060",
      "detail": "ENRICHED — CVE-2021-42060. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-42113",
      "detail": "ENRICHED — CVE-2021-42113. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-42554",
      "detail": "ENRICHED — CVE-2021-42554. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-43323",
      "detail": "ENRICHED — CVE-2021-43323. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-43522",
      "detail": "ENRICHED — CVE-2021-43522. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-43615",
      "detail": "ENRICHED — CVE-2021-43615. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-44228",
      "detail": "ENRICHED — CVE-2021-44228 (Apache Log4j2). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-45969",
      "detail": "ENRICHED — CVE-2021-45969. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-45970",
      "detail": "ENRICHED — CVE-2021-45970. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-45971",
      "detail": "ENRICHED — CVE-2021-45971. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-47210",
      "detail": "ENRICHED — CVE-2021-47210 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-47253",
      "detail": "ENRICHED — CVE-2021-47253 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-47335",
      "detail": "ENRICHED — CVE-2021-47335 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-47410",
      "detail": "ENRICHED — CVE-2021-47410 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-47431",
      "detail": "ENRICHED — CVE-2021-47431 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-47610",
      "detail": "ENRICHED — CVE-2021-47610 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-24030",
      "detail": "ENRICHED — CVE-2022-24030. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-24031",
      "detail": "ENRICHED — CVE-2022-24031. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-24069",
      "detail": "ENRICHED — CVE-2022-24069. Received CVSS 8.2 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-48628",
      "detail": "ENRICHED — CVE-2022-48628 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2023-44487",
      "detail": "ENRICHED — CVE-2023-44487 (IETF HTTP/2). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-20353",
      "detail": "ENRICHED — CVE-2024-20353 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 8.6 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-20359",
      "detail": "ENRICHED — CVE-2024-20359 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 6.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-20481",
      "detail": "ENRICHED — CVE-2024-20481 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 5.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-20333",
      "detail": "ENRICHED — CVE-2025-20333 (Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense). Received CVSS 9.9 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-20362",
      "detail": "ENRICHED — CVE-2025-20362 (Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense). Received CVSS 8.6 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
