{
  "day": "2026-08-12",
  "boundary": "UTC calendar day",
  "published_count": 433,
  "by_severity": {
    "CRITICAL": 69,
    "HIGH": 149,
    "MEDIUM": 185,
    "LOW": 16
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 14,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-73296",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02609,
      "epss_percentile": 0.84163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-306",
      "title": "Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73296"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-73297",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01616,
      "epss_percentile": 0.74077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-918",
      "title": "Microsoft UFO: IPv6 transition address bypass of SSRF guard in URL validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73297"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-71471",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01452,
      "epss_percentile": 0.71309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-829",
      "title": "Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71471"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-73299",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01215,
      "epss_percentile": 0.66132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "prompty",
      "cwe": "CWE-94",
      "title": "Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73299"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-47717",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01203,
      "epss_percentile": 0.65776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-201",
      "title": "FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47717"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-16956",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01043,
      "epss_percentile": 0.61409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-78",
      "title": "IBM Db2 Mirror for i is vulnerable to OS command injection []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16956"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-63294",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01016,
      "epss_percentile": 0.60559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-59",
      "title": "Root RCE via image backup.yaml symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63294"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-49481",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00882,
      "epss_percentile": 0.56366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seriousm4x",
      "product": "UpSnap",
      "cwe": "CWE-78",
      "title": "UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49481"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-18683",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00807,
      "epss_percentile": 0.54012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By privilege escalation in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18683"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-67260",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00779,
      "epss_percentile": 0.53068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-502",
      "title": "Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67260"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2025-15684",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0071,
      "epss_percentile": 0.50705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-617",
      "title": "Open5GS CER init.c diam_log_func assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15684"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-73298",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00677,
      "epss_percentile": 0.49466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "Container-Migration-Solution-Accelerator",
      "cwe": "CWE-639",
      "title": "Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/write/delete processes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73298"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-73519",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00617,
      "epss_percentile": 0.46891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfsoftwaresystemsltd",
      "product": "WolfStack",
      "cwe": "CWE-798",
      "title": "WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73519"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-49819",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00615,
      "epss_percentile": 0.46783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seriousm4x",
      "product": "UpSnap",
      "cwe": "CWE-78",
      "title": "UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49819"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2025-15687",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00612,
      "epss_percentile": 0.46624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-404",
      "title": "Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15687"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-67587",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00611,
      "epss_percentile": 0.46607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-502",
      "title": "Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67587"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-16051",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00589,
      "epss_percentile": 0.45586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wpmudev-updates",
      "cwe": "CWE-94",
      "title": "WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16051"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-70468",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00587,
      "epss_percentile": 0.45514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiManager",
      "cwe": "CWE-288",
      "title": "A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70468"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-73330",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00587,
      "epss_percentile": 0.45489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-1336",
      "title": "CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73330"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2025-41769",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00586,
      "epss_percentile": 0.45464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "AXC F 1152",
      "cwe": "CWE-120",
      "title": "Unauthenticated Buffer Overflow in PROFINET Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41769"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-59242",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00584,
      "epss_percentile": 0.45378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-502",
      "title": "Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59242"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-18391",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00575,
      "epss_percentile": 0.44902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WooCommerce Subscriptions",
      "cwe": "CWE-434",
      "title": "WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18391"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-73415",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00574,
      "epss_percentile": 0.44874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-79",
      "title": "jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73415"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-68868",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0057,
      "epss_percentile": 0.44695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Google provider",
      "cwe": "CWE-1220",
      "title": "Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68868"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-15039",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00569,
      "epss_percentile": 0.44636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "giftware",
      "cwe": "CWE-434",
      "title": "Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15039"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-67282",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00568,
      "epss_percentile": 0.44563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fabrikar.com",
      "product": "Fabrik extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67282"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-71408",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00556,
      "epss_percentile": 0.4393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiOS",
      "cwe": "CWE-770",
      "title": "A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71408"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-13476",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00549,
      "epss_percentile": 0.43599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Informix Dynamic Server",
      "cwe": "CWE-78",
      "title": "IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13476"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-70465",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00548,
      "epss_percentile": 0.43548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiClientWindows",
      "cwe": "CWE-120",
      "title": "A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70465"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-17218",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00545,
      "epss_percentile": 0.43381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17218"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-73240",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00541,
      "epss_percentile": 0.43177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-88",
      "title": "Apache Allura: Git command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73240"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2025-59321",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00535,
      "epss_percentile": 0.42854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1188",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59321"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-17431",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00534,
      "epss_percentile": 0.42793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MITHALDU",
      "product": "PDF::WebKit",
      "cwe": "CWE-73",
      "title": "PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17431"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-71193",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Designate",
      "cwe": "CWE-863",
      "title": "In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71193"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-16906",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00524,
      "epss_percentile": 0.42237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Domain Name System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16906"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-16904",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00524,
      "epss_percentile": 0.42261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By improper privilege management in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16904"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-48553",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.42218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios Enterprises, LLC.",
      "product": "Nagios Core",
      "cwe": "CWE-78",
      "title": "Nagios Core / XI Authenticated RCE via Custom-Variable Macro Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48553"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-48554",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.42217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios Enterprises, LLC.",
      "product": "Nagios Core",
      "cwe": "CWE-78",
      "title": "Nagios Core / XI Authenticated RCE via Unfiltered NOTIFICATION-Family Macro Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48554"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-16860",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00512,
      "epss_percentile": 0.41461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-427",
      "title": "IBM i is Affected By Remote Code Execution Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16860"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-11325",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00512,
      "epss_percentile": 0.41462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloudflare",
      "product": "https://github.com/cloudflare/pages-action",
      "cwe": "CWE-78",
      "title": "cloudflare/pages-action is deprecated — migration required by September 18th, 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11325"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-18669",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00512,
      "epss_percentile": 0.41461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-250",
      "title": "IBM i is Affected By A Privilege Escalation Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18669"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-26035",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0051,
      "epss_percentile": 0.41398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiWeb",
      "cwe": "CWE-287",
      "title": "An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26035"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2025-15686",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0051,
      "epss_percentile": 0.41359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-404",
      "title": "Open5GS HSS Service fd_msg_sess_get denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15686"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-71194",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00509,
      "epss_percentile": 0.41299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Designate",
      "cwe": "CWE-669",
      "title": "In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71194"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-18713",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18713"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-71407",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00494,
      "epss_percentile": 0.40423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiOS",
      "cwe": "CWE-121",
      "title": "A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71407"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-17110",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-250",
      "title": "IBM i is Affected By Multiple Vulnerabilities in SQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17110"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-58076",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.39791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-502",
      "title": "Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58076"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2024-14044",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00482,
      "epss_percentile": 0.39682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14044"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-73414",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0048,
      "epss_percentile": 0.39527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ericcornelissen",
      "product": "shescape",
      "cwe": "CWE-78",
      "title": "Shescape: Shell injection via unescaped parentheses on Windows with CMD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73414"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-54183",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00467,
      "epss_percentile": 0.38704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Airflow Variables were not masked in the UI for authenticated users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54183"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-73418",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextauthjs",
      "product": "next-auth",
      "cwe": "CWE-20",
      "title": "NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73418"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2025-59319",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-290",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59319"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-17083",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00455,
      "epss_percentile": 0.37943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in the Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17083"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-18961",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fahdaslam",
      "product": "Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect",
      "cwe": "CWE-287",
      "title": "Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18961"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-73294",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "semaphoreui",
      "product": "semaphore",
      "cwe": "CWE-78",
      "title": "Semaphore U: OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73294"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2025-59326",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59326"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-65941",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "WhatsUp Gold",
      "cwe": "CWE-73",
      "title": "WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65941"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-17266",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00437,
      "epss_percentile": 0.36576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17266"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-73237",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0043,
      "epss_percentile": 0.3603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-80",
      "title": "Apache Allura: XSS in markdown pipeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73237"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-73238",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0043,
      "epss_percentile": 0.3603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-80",
      "title": "Apache Allura: XSS in code display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73238"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-73407",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-22",
      "title": "Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152))",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73407"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-17417",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Remote Code Execution Vulnerabilities [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17417"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-17642",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Remote Code Execution Vulnerabilities [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17642"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-68968",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-436",
      "title": "Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68968"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-57858",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cal.com",
      "product": "Cal.com Self-Hosted (Cal.diy)",
      "cwe": "CWE-79",
      "title": "Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57858"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-19311",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "OpenSearch",
      "cwe": "CWE-475",
      "title": "Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19311"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-7427",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00414,
      "epss_percentile": 0.34716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7427"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-49467",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smp46",
      "product": "pingvin-share-x",
      "cwe": "CWE-303",
      "title": "TOTP enrollment hijack: password gate skipped due to unawaited promise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49467"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-16907",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in the Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16907"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-19654",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19654"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-73293",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "semaphoreui",
      "product": "semaphore",
      "cwe": "CWE-269",
      "title": "Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73293"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-67579",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.3347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-89",
      "title": "Filter expression injection via forged keyset pagination cursor in Ash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67579"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-17094",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Path Traversal Vulnerability in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17094"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-18663",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-415",
      "title": "389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18663"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-73500",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33,
      "kev": false,
      "kev_due_at": null,
      "vendor": "etcd-io",
      "product": "etcd",
      "cwe": "CWE-770",
      "title": "etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73500"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-19594",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake Python APIs",
      "cwe": "CWE-22",
      "title": "Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19594"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-10543",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-285",
      "title": "IBM® Db2® is vulnerable to privilege escalation with a specially crafted query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10543"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-16770",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MITHALDU",
      "product": "PDF::WebKit",
      "cwe": "CWE-88",
      "title": "PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16770"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-65017",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65017"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2025-41770",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "AXC F 1152",
      "cwe": "CWE-770",
      "title": "Unauthenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41770"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-16931",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-835",
      "title": "IBM i is Affected By A Denial of Service Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16931"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-17271",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-770",
      "title": "IBM i is Affected By Multiple Vulnerabilities in the Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17271"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-67286",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67286"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-18675",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong Inc.",
      "product": "Kong Mesh",
      "cwe": "CWE-248",
      "title": "Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18675"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-17095",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-915",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17095"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-63293",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00382,
      "epss_percentile": 0.31522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-59",
      "title": "Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63293"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2025-15685",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS freeDiameter memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15685"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-73300",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-89",
      "title": "Budibase: SQL Injection via `multipleStatements: true`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73300"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-19001",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00377,
      "epss_percentile": 0.30968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-190",
      "title": "MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19001"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-10534",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00376,
      "epss_percentile": 0.3088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-121",
      "title": "IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10534"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-67285",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67285"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-68760",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-287",
      "title": "Potential remember-me authentication bypass in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68760"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-73406",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-200",
      "title": "Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73406"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-64826",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rConfig",
      "product": "rConfig",
      "cwe": "CWE-22",
      "title": "rConfig < 8.2.13 Path Traversal File Read via FileDownloadController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64826"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-73268",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-94",
      "title": "Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73268"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-50561",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xerrors",
      "product": "Yuxi",
      "cwe": "CWE-287",
      "title": "Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50561"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-12005",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-78",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12005"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-12618",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-74",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12618"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-18106",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.30044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18106"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-73499",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.2975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "etcd-io",
      "product": "etcd",
      "cwe": "CWE-863",
      "title": "etcd: Watch API authorization bypass via open-ended range requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73499"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-19004",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-122",
      "title": "MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19004"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2025-59322",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-329",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59322"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-71469",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-770",
      "title": "Acm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticated memory-exhaustion dos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71469"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-73374",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vulnerability-lookup",
      "product": "vulnerability-lookup",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) via Unescaped CNA Reference Tags in vulnerability-lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73374"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-68969",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-532",
      "title": "Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68969"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-63298",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-78",
      "title": "LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63298"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-73263",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prowler-cloud",
      "product": "prowler",
      "cwe": "CWE-78",
      "title": "Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73263"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-18749",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CERT/CC",
      "product": "VINCE",
      "cwe": "CWE-639",
      "title": "CVE-2026-18749",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18749"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-44741",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-89",
      "title": "Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44741"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-19566",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Net::CIDR::Set",
      "cwe": "CWE-789",
      "title": "Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19566"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-69106",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-20",
      "title": "Potential cache poisoning in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69106"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-12004",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-134",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12004"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-73412",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.27987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ericcornelissen",
      "product": "shescape",
      "cwe": "CWE-78",
      "title": "Shescape: Path disclosure on Unix with Zsh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73412"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-73285",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-863",
      "title": "RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73285"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-73493",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4s",
      "product": "blaze",
      "cwe": "CWE-770",
      "title": "http4s-blaze-server: Unbounded WebSocket message aggregation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73493"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-16856",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Domain Name System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16856"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-66898",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-22",
      "title": "Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66898"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-73501",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkin",
      "product": "kin-openapi",
      "cwe": "CWE-287",
      "title": "kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73501"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-72508",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00343,
      "epss_percentile": 0.27389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-250",
      "title": "Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72508"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-13105",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Client Solutions",
      "cwe": "CWE-22",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13105"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-15803",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.2745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse RDF4J",
      "cwe": "CWE-611",
      "title": "In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an incomplete fix for CVE-2018-1000644: the earlier fix did not cover all parser entry points. The issue is resolved in RDF4J 5.3.2, which rejects or disables DOCTYPE declarations, external entities, and external DTD loading by default.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15803"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-73239",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-280",
      "title": "Apache Allura: Missing permission checks IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73239"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-16863",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Out-of-Bounds Read Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16863"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-68076",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-639",
      "title": "Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68076"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-68756",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-502",
      "title": "Potential insecure deserialization in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68756"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-19643",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.26967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-sdk-cpp",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19643"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-73413",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ericcornelissen",
      "product": "shescape",
      "cwe": "CWE-400",
      "title": "Shescape: Quadratic-time denial of service in flag-protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73413"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-73411",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ericcornelissen",
      "product": "shescape",
      "cwe": "CWE-116",
      "title": "Shescape: Home-directory disclosure in assignment context on Unix with Dash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73411"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-68752",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-269",
      "title": "Project Resource Managers may escalate privileges in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68752"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-16480",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-602",
      "title": "IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16480"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-16494",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16494"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-17248",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in the Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17248"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-73430",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-754",
      "title": "Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73430"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-68971",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-862",
      "title": "Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68971"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-73498",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73498"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-72786",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-285",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72786"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-64639",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00326,
      "epss_percentile": 0.25585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-266",
      "title": "Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64639"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-17109",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-20",
      "title": "IBM i is Affected By Multiple Vulnerabilities in SQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17109"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-73427",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00326,
      "epss_percentile": 0.25568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "basecamp",
      "product": "trix",
      "cwe": "CWE-79",
      "title": "Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73427"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-12359",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-287",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12359"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-11932",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-835",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11932"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-73306",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.2496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-204",
      "title": "Budibase: Account Enumeration via Login Lockout Response Differential",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73306"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-18952",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Opensearch",
      "cwe": "CWE-918",
      "title": "Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18952"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-73264",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prowler-cloud",
      "product": "prowler",
      "cwe": "CWE-918",
      "title": "Prowler: Server-Side Request Forgery (SSRF) in Lighthouse Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73264"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2024-27253",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DOORS Next",
      "cwe": "CWE-287",
      "title": "IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-27253"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-14925",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Import WP",
      "cwe": "CWE-200",
      "title": "Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14925"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-18677",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong Inc.",
      "product": "Kong Mesh",
      "cwe": "CWE-290",
      "title": "Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18677"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-73307",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF via bare fetch() in uploadUrl during AI table generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73307"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-18235",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18235"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-18673",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong Inc.",
      "product": "Kong Mesh",
      "cwe": "CWE-200",
      "title": "Kong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18673"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-73422",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-79",
      "title": "Astro: Reflected XSS via unescaped View Transition animation properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73422"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-70466",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiWeb",
      "cwe": "CWE-184",
      "title": "A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70466"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-62420",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.2346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-863",
      "title": "Cross-project cluster migration bypasses project restrictions via cluster notification flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62420"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-72806",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Authentication Bypass via Attribute View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72806"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-12233",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.2336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-665",
      "title": "Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12233"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-67287",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67287"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-73265",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-862",
      "title": "RustFS: Version-specific object reads authorize the non-version action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73265"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-18366",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.2297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Manager",
      "cwe": "CWE-269",
      "title": "Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18366"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-19642",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-sdk-cpp",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19642"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-18744",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CERT/CC",
      "product": "VINCE",
      "cwe": "CWE-639",
      "title": "CVE-2026-18744",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18744"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-72526",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-441",
      "title": "Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72526"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-42018",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-287",
      "title": "Anonymous user token generation exposure in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42018"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-19426",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.2232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FitSoft",
      "product": "POS System",
      "cwe": "CWE-306",
      "title": "FitSoft｜POS Sytstem - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19426"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-16627",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16627"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-13613",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "KiviCare",
      "cwe": "CWE-89",
      "title": "KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13613"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-16033",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-22",
      "title": "Arbitrary file read+write on host via templates/ symlink in malicious image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16033"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-19002",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-120",
      "title": "Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19002"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-72789",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00293,
      "epss_percentile": 0.21898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72789"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-73308",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-200",
      "title": "Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73308"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-72788",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-863",
      "title": "SiYuan before v3.7.4 Information Disclosure via UILayout Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72788"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-63300",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-862",
      "title": "Cross-project instance move bypasses all project restrictions allowing host command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63300"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-66659",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Essekia",
      "product": "Tablesome Table",
      "cwe": "CWE-89",
      "title": "WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66659"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-66381",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-22",
      "title": "Repository readers may access content outside configured upstream paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66381"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-73429",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-704",
      "title": "Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73429"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-17485",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Denial of Service Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17485"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-73495",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4s",
      "product": "blaze",
      "cwe": "CWE-444",
      "title": "blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73495"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-18888",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-787",
      "title": "MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18888"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-19656",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00286,
      "epss_percentile": 0.21182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SCADA-LTS",
      "product": "ScadaLTS",
      "cwe": "CWE-862",
      "title": "ScadaLTS Authenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19656"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-73405",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vulnerability-lookup",
      "product": "vulnerability-lookup",
      "cwe": "CWE-862",
      "title": "Authorization Bypass in SSE Pub/Sub Allows Unconfirmed Accounts to Access Stream Events in vulnerability-lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73405"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-63299",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-770",
      "title": "Storage volume cross-project move and snapshot restore bypass project disk limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63299"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-73284",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-269",
      "title": "RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73284"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-72808",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getFileAnnotation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72808"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-18474",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18474"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-68433",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: bound get_version reply decode to front len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68433"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-6821",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6821"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-16253",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Total Upkeep",
      "cwe": "CWE-200",
      "title": "Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16253"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-18049",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-200",
      "title": "WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18049"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-73431",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vulnerability-lookup",
      "product": "vulnerability-lookup",
      "cwe": "CWE-294",
      "title": "Reusable Account Activation and Recovery Tokens Allow Repeated Account Takeover in vulnerability-lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73431"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-17082",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By Multiple Vulnerabilities in the Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17082"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-49473",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cedar-policy",
      "product": "authorization-for-expressjs",
      "cwe": "CWE-436",
      "title": "@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49473"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-66375",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Low-privilege users may remove protected Artifactory metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66375"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-69107",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.2001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Potential unauthorized artifact access in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69107"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-73326",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-862",
      "title": "CamaleonCMS Missing Authorization via Plugin Administration Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73326"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-73291",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seerr-team",
      "product": "seerr",
      "cwe": "CWE-22",
      "title": "Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73291"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-13361",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Informix Dynamic Server",
      "cwe": "CWE-121",
      "title": "IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13361"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-17616",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00271,
      "epss_percentile": 0.19402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-310",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17616"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-47718",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-287",
      "title": "FUXA provides guest and invalid-token access to protected read APIs in secure mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47718"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-18499",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.1926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-285",
      "title": "IBM WebSphere Application Server Liberty is affected by a privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18499"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-12976",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": "CWE-200",
      "title": "LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12976"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-13168",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-200",
      "title": "Eventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13168"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-17420",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in SQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17420"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-48550",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.1859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios Enterprises, LLC.",
      "product": "Nagios Core",
      "cwe": "CWE-79",
      "title": "Nagios Core / XI cmd.cgi Reflected XSS via NagFormId Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48550"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-68431",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: validate minimum PDU size for transform requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68431"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-73331",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-89",
      "title": "CamaleonCMS 2.9.1 Authenticated SQL Injection via Post Slug Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73331"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-66384",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-22",
      "title": "Authenticated users may write data outside the intended Docker cache path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66384"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-18789",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ezoic",
      "cwe": "CWE-862",
      "title": "Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18789"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-15216",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15216"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-15217",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15217"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-15423",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15423"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-17276",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17276"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-71473",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.1771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-915",
      "title": "Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spoke",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71473"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-73325",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fujitsu Research",
      "product": "OneCompression",
      "cwe": "CWE-502",
      "title": "Fujitsu OneCompression 1.2.0 Arbitrary Code Execution via torch.load Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73325"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-68758",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Authenticated users may access restricted Artifactory support information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68758"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-72796",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Access Control Bypass via Static Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72796"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-70467",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00257,
      "epss_percentile": 0.17599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiSIEM",
      "cwe": "CWE-918",
      "title": "A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70467"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-72798",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00256,
      "epss_percentile": 0.17432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via renderAttributeView",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72798"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-72804",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.17231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-200",
      "title": "SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72804"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-66382",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-22",
      "title": "Authenticated users may write files outside the intended Artifactory work directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66382"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-17111",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00251,
      "epss_percentile": 0.16741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-89",
      "title": "IBM i is Affected By Multiple Vulnerabilities in SQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17111"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-17222",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-89",
      "title": "IBM i is Affected By Multiple Vulnerabilities in SQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17222"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-73301",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-862",
      "title": "Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73301"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-72794",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00249,
      "epss_percentile": 0.1655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-522",
      "title": "siyuan before v3.7.4 Session Cookie Key Disclosure via getConf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72794"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-46382",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "meeting-room-booking-system",
      "product": "mrbs-code",
      "cwe": "CWE-918",
      "title": "Meeting Room Booking System has server-side request forgery in import functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46382"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-46688",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "meeting-room-booking-system",
      "product": "mrbs-code",
      "cwe": "CWE-601",
      "title": "Meeting Room Booking System has an unauthenticated open redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46688"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-13267",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-302",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13267"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-67283",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tabaoca.org",
      "product": "Cotton Cloud extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - tabaoca.org - Improper ACL implementation allows allow file operations in Cotton Cloud < 2.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67283"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-63296",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.16194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-863",
      "title": "Project restriction bypass via instance migration config override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63296"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-73288",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-693",
      "title": "RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73288"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-73491",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00245,
      "epss_percentile": 0.15996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flavorjones",
      "product": "loofah",
      "cwe": "CWE-184",
      "title": "Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73491"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-73492",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00245,
      "epss_percentile": 0.15956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flavorjones",
      "product": "loofah",
      "cwe": "CWE-79",
      "title": "Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73492"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-66377",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Anonymous users may access restricted Artifactory repository information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66377"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-18048",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-73",
      "title": "WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18048"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-11923",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-287",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11923"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-17419",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-89",
      "title": "IBM i is Affected By Multiple Vulnerabilities in SQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17419"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-73290",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-863",
      "title": "RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73290"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-4879",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4879"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-18433",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18433"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-65937",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "WhatsUp Gold",
      "cwe": "CWE-79",
      "title": "WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65937"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-73432",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vulnerability-lookup",
      "product": "vulnerability-lookup",
      "cwe": "CWE-918",
      "title": "Stored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Internal Services in vulnerability-lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73432"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-72793",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-522",
      "title": "SiYuan before v3.7.4 Information Disclosure via /api/system/getConf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72793"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-72795",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via Embed Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72795"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-72801",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-522",
      "title": "SiYuan before v3.7.4 Information Disclosure via Encryption Key Material",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72801"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-8667",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8667"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-73286",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-863",
      "title": "RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73286"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-65939",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "WhatsUp Gold",
      "cwe": "CWE-22",
      "title": "WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65939"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-68753",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Anonymous users may access restricted Artifactory content under specific configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68753"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-72790",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getNotebookInfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72790"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-72791",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getAttributeViewFieldViews",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72791"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-72792",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-863",
      "title": "SiYuan before v3.7.4 Information Disclosure via Tag API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72792"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-72797",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72797"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-72799",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via Path Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72799"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-72800",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via Unfiltered API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72800"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-72802",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-639",
      "title": "SiYuan before v3.7.4 Information Disclosure via resolveAssetPath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72802"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-72803",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getBlockAttrs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72803"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-72805",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via Block Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72805"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-17445",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-250",
      "title": "IBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17445"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-18750",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CERT/CC",
      "product": "VINCE",
      "cwe": "CWE-639",
      "title": "CVE-2026-18750",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18750"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-15388",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Cookie Consent",
      "cwe": "CWE-863",
      "title": "Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15388"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-18144",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.1488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-285",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18144"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-13171",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-284",
      "title": "Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13171"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-47227",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-639",
      "title": "Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules/categories.php`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47227"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-73269",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-269",
      "title": "Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73269"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-16538",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.14348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Wallet for WooCommerce",
      "cwe": "CWE-284",
      "title": "TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16538"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-64954",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-862",
      "title": "Velociraptor collect_client() Permissions Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64954"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-73303",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-639",
      "title": "Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73303"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-73289",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-863",
      "title": "RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73289"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-19228",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19228"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-59244",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.1405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-312",
      "title": "Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59244"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-68970",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-312",
      "title": "Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68970"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-18676",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong Inc.",
      "product": "Kong Mesh",
      "cwe": "CWE-346",
      "title": "Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18676"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-73329",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.13927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-79",
      "title": "CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73329"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-73332",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.13927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-89",
      "title": "CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73332"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-68759",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-347",
      "title": "Integration credential holders may impersonate users in JFrog Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68759"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2025-59325",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-311",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59325"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-11937",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security Verify Access",
      "cwe": "CWE-416",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11937"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-70398",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00225,
      "epss_percentile": 0.13476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-441",
      "title": "Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70398"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2025-9486",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00225,
      "epss_percentile": 0.13429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-266",
      "title": "Incorrect Privilege Assignment in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9486"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-64955",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-1236",
      "title": "Velociraptor CSV Formula Injection in Export Pipeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64955"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-18652",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.1308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-862",
      "title": "Velociraptor STACK Type Download Path Bypasses Denied Prefix Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18652"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-16977",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Form Maker by 10Web",
      "cwe": "CWE-89",
      "title": "Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16977"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-18057",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Manager",
      "cwe": "CWE-89",
      "title": "Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18057"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-18230",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18230"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-47233",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-862",
      "title": "Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incomplete fix of #2024",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47233"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-68754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Publishers without delete permission can overwrite docker layer information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68754"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-49349",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regclient",
      "product": "regclient",
      "cwe": "CWE-522",
      "title": "regclient may leak authentication credentials to external blob stores",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49349"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-16747",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-74",
      "title": "Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16747"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-18943",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.1264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPC Admin Columns",
      "cwe": "CWE-200",
      "title": "WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18943"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-18726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18726"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-73262",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prowler-cloud",
      "product": "prowler",
      "cwe": "CWE-79",
      "title": "Prowler: Stored XSS in HTML reports through unescaped cloud resource tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73262"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-63295",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-863",
      "title": "Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63295"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-47231",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-639",
      "title": "Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47231"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-66878",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-639",
      "title": "Multicloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66878"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-73122",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-269",
      "title": "Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73122"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-65940",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "WhatsUp Gold",
      "cwe": "CWE-276",
      "title": "WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65940"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-73287",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-862",
      "title": "RustFS: FTPS MKD bypasses IAM CreateBucket authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73287"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-16737",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Travel Engine",
      "cwe": "CWE-639",
      "title": "WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16737"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-18035",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Access Manager",
      "cwe": "CWE-862",
      "title": "User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18035"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-19503",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Atlas SQL ODBC Driver",
      "cwe": "CWE-20",
      "title": "Insufficient OIDC endpoint validation could invoke unintended local protocol handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19503"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-17268",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-294",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17268"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-65370",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "servicetalk",
      "cwe": "CWE-444",
      "title": "ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65370"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-67284",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.1112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tabaoca.org",
      "product": "Cotton Cloud extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - tabaoca.org - Improper ACL checks allow file operations in Cotton Cloud < 2.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67284"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-72809",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.11039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-290",
      "title": "SiYuan before v3.7.4 Authentication Bypass via Localhost Trust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72809"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-19073",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Order Sync with Zendesk for WooCommerce",
      "cwe": "CWE-200",
      "title": "Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19073"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-18148",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.1104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-117",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18148"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-18244",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18244"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-66378",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Authenticated users may access private NuGet metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66378"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-66379",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Authenticated users may view private Puppet module metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66379"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-66380",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Authenticated users may access private OCI referrer metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66380"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-70547",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Potential unauthorized metadata exposure in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70547"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-47226",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-639",
      "title": "Admidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47226"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-19588",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-680",
      "title": "Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19588"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-72807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.1013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan before v3.7.4 SQL Injection via queryBlocks template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72807"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-19587",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19587"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-18727",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-191",
      "title": "Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18727"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-19657",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SCADA-LTS",
      "product": "ScadaLTS",
      "cwe": "CWE-79",
      "title": "ScadaLTS Unauthenticated Reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19657"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-14858",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Crowdfunding",
      "cwe": "CWE-639",
      "title": "WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14858"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-63297",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00196,
      "epss_percentile": 0.0974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-367",
      "title": "Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63297"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-15045",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Wallet System for WooCommerce",
      "cwe": "CWE-472",
      "title": "Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15045"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-68757",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-347",
      "title": "Potential improper SAML signature verification in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68757"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-16990",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payment Button for PayPal",
      "cwe": null,
      "title": "Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16990"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-73419",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextauthjs",
      "product": "next-auth",
      "cwe": "CWE-345",
      "title": "NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73419"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-18246",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-436",
      "title": "IBM i is Affected By security restrictions bypass in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18246"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-68755",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-863",
      "title": "Bundle writers may alter trusted release information in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68755"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-73409",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.0915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-203",
      "title": "Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73409"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-18098",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-346",
      "title": "IBM i is Affected By XML injection flaw in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18098"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-72787",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72787"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-73292",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "semaphoreui",
      "product": "semaphore",
      "cwe": "CWE-352",
      "title": "Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73292"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-65926",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00188,
      "epss_percentile": 0.08751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Private Release Bundle versions may be disclosed under specific configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65926"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-73295",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "squidfunk",
      "product": "mkdocs-material",
      "cwe": "CWE-79",
      "title": "Material for MkDocs: DOM XSS in search suggestions via query parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73295"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-13177",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-639",
      "title": "Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13177"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-13612",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.0843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "KiviCare",
      "cwe": "CWE-639",
      "title": "KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13612"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-14857",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Crowdfunding",
      "cwe": "CWE-639",
      "title": "WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14857"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-14859",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Crowdfunding",
      "cwe": "CWE-284",
      "title": "WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14859"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-18046",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Cookie Consent",
      "cwe": "CWE-863",
      "title": "Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18046"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-18099",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-79",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18099"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-73423",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-352",
      "title": "Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73423"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-9318",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jazzband",
      "product": "tablib",
      "cwe": "CWE-79",
      "title": "tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9318"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2025-59320",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-922",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59320"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-73490",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flavorjones",
      "product": "loofah",
      "cwe": "CWE-79",
      "title": "Loofah: SVG `href` attribute bypasses local-reference restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73490"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-19130",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-639",
      "title": "Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19130"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-18847",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.0741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-346",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18847"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-47230",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-639",
      "title": "Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47230"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-64952",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.0723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-863",
      "title": "Velociraptor Hunt Deletion With Insufficient Permission Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64952"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-48551",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios Enterprises, LLC.",
      "product": "Nagios Core",
      "cwe": "CWE-352",
      "title": "Nagios Core / XI CSRF Protection Bypass via Double-Submit Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48551"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-17418",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-89",
      "title": "IBM i is Affected By Multiple Vulnerabilities in SQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17418"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-16294",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PowerPress Podcasting plugin by Blubrry",
      "cwe": "CWE-918",
      "title": "Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16294"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-73425",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.0688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-185",
      "title": "@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73425"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-68443",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00169,
      "epss_percentile": 0.06641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68443"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-18150",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-362",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18150"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-68429",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68429"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-68430",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx8: drop unecessary BUG_ON()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68430"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-68434",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68434"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-68444",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68444"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-16694",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-79",
      "title": "IBM i is Affected By Stored Cross-site Scripting for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16694"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-48552",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios Enterprises, LLC.",
      "product": "Nagios Core",
      "cwe": "CWE-79",
      "title": "Nagios Core / XI DOM-based XSS via jsonquery.js",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48552"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-70560",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ultimate Fosters",
      "product": "Ultimate POS (Stock Management & Point of Sale)",
      "cwe": "CWE-79",
      "title": "Ultimate POS Stored XSS via First Name Field in Leave Notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70560"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-7366",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataPower Gateway 11.0.0",
      "cwe": "CWE-362",
      "title": "IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7366"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-17013",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-79",
      "title": "WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17013"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2025-41771",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "AXC F 1152",
      "cwe": "CWE-89",
      "title": "SQL injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41771"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-64951",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00163,
      "epss_percentile": 0.06032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-369",
      "title": "Velociraptor DoS triggered by Divide by Zero panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64951"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-49466",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dartiss",
      "product": "draft-list",
      "cwe": "CWE-79",
      "title": "Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49466"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-15249",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Patterns Kit",
      "cwe": "CWE-79",
      "title": "Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15249"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-16066",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Welcart e-Commerce",
      "cwe": "CWE-79",
      "title": "Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16066"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-18250",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-362",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18250"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-65938",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software Corporation",
      "product": "WhatsUp Gold",
      "cwe": "CWE-602",
      "title": "WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65938"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-66376",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-613",
      "title": "Deleted users may temporarily retain access to JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66376"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-13622",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Container Native Virtualization 4.12",
      "cwe": "CWE-22",
      "title": "Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13622"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-68437",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/imagination: Fit paired fragment job in the correct CCCB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68437"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-68449",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68449"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-68450",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: free mapping node on duplicate reloc root insert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68450"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-68439",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68439"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-68435",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Fix address space mismatch in kexec command line lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68435"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-68448",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.05175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovl: check access to copy_file_range source with src mounter creds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68448"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-18962",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-639",
      "title": "WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18962"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-19052",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProSolution WP Client",
      "cwe": "CWE-862",
      "title": "ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19052"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2025-59324",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0015,
      "epss_percentile": 0.0471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-347",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59324"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-16695",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.0469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Client Solutions",
      "cwe": "CWE-78",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16695"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2025-59327",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.0471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-347",
      "title": "In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59327"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-68441",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00148,
      "epss_percentile": 0.0456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68441"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-13094",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Client Solutions",
      "cwe": "CWE-94",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13094"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-18097",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-532",
      "title": "IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18097"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-68436",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: use kvzalloc to allocate struct dc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68436"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-68438",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smp: Make CSD lock acquisition atomic for debug mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68438"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-6484",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Insyde Software",
      "product": "InsydeH2O",
      "cwe": "CWE-1277",
      "title": "Lack of verified boot to certain FV may cause arbitrary code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6484"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-64927",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-639",
      "title": "Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and configmap mutation via spec.secretref.namespace confused deputy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64927"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-19050",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProSolution WP Client",
      "cwe": "CWE-918",
      "title": "ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19050"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-19217",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.0328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19217"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-73433",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.0315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "gst-plugins-good",
      "cwe": "CWE-191",
      "title": "Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73433"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-73434",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "gst-plugins-good",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73434"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-18096",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00131,
      "epss_percentile": 0.03138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-770",
      "title": "IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18096"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-49262",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00131,
      "epss_percentile": 0.0317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aimeos",
      "product": "pagible",
      "cwe": "CWE-367",
      "title": "Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49262"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-47234",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.0308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-200",
      "title": "Admidio writes session IDs and auto-login cookie values to application logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47234"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-68432",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: require CAP_NET_ADMIN in the device netns for changelink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68432"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-69105",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-345",
      "title": "Potential package cache integrity issue in JFrog Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69105"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-16999",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ministry of Justice",
      "product": "UYAP Document Editor",
      "cwe": "CWE-611",
      "title": "XXE in Ministry of Justice's UYAP Document Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16999"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-19003",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-121",
      "title": "MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19003"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-68445",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vc4: Prevent shader BO mappings from becoming writable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68445"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-68440",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: txgbe: fix heap overflow when reading module EEPROM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68440"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-46731",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager (DDPM Windows)",
      "cwe": "CWE-290",
      "title": "Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46731"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-59914",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager (DDPM Windows)",
      "cwe": "CWE-284",
      "title": "Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59914"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-19548",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19548"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-68446",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vmwgfx: Validate vmw_surface_metadata::array_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68446"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-18679",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong Inc.",
      "product": "Kong Mesh",
      "cwe": "CWE-295",
      "title": "Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18679"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-15141",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-WR820N v2",
      "cwe": "CWE-346",
      "title": "Referer Validation Bypass in TL-WR820N Web Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15141"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-68442",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68442"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-71846",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-250",
      "title": "Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71846"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-14479",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Installer",
      "cwe": "CWE-1285",
      "title": "Denial of Service in Autodesk Installer IPC Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14479"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-16621",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payment Gateway for PayPal on WooCommerce",
      "cwe": null,
      "title": "Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16621"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-13433",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00113,
      "epss_percentile": 0.0167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Client Solutions",
      "cwe": "CWE-494",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13433"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-19502",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Schema Builder CLI",
      "cwe": "CWE-532",
      "title": "Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19502"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-15213",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Welcart e-Commerce",
      "cwe": null,
      "title": "Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15213"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-17008",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quick Paypal Payments",
      "cwe": null,
      "title": "Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17008"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-14478",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Installer",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment in Autodesk Installer Named Pipes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14478"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-59916",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager (DDPM Windows)",
      "cwe": "CWE-290",
      "title": "Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59916"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-59917",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager (DDPM Windows)",
      "cwe": "CWE-284",
      "title": "Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59917"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-68447",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68447"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-47228",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.0139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-352",
      "title": "Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47228"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-18171",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Sandboxes",
      "cwe": "CWE-863",
      "title": "Docker Sandboxes read-only runtime mount writable through its shared-export alias",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18171"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-47232",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-352",
      "title": "Admidio PKCS#12 private key export action lacks CSRF protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47232"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2025-59323",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-345",
      "title": "CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59323"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-12232",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12232"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-13367",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Informix Dynamic Server",
      "cwe": "CWE-284",
      "title": "IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13367"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-18044",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.001,
      "epss_percentile": 0.00949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Estatik Real Estate Plugin",
      "cwe": "CWE-345",
      "title": "Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18044"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-18678",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong Inc.",
      "product": "Kong Mesh",
      "cwe": "CWE-295",
      "title": "Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18678"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-12235",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12235"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-47229",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-352",
      "title": "Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47229"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-53996",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The NetBSD Foundation",
      "product": "NetBSD",
      "cwe": "CWE-862",
      "title": "NetBSD hdaudio(4) Driver Privilege Bypass Use-After-Free via HDAUDIO_FGRP_SETCONFIG ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53996"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-50544",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NortheBridge",
      "product": "luminalshine",
      "cwe": "CWE-379",
      "title": "NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50544"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-12234",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00081,
      "epss_percentile": 0.00218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-367",
      "title": "TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12234"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-14866",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00081,
      "epss_percentile": 0.00241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Client Solutions",
      "cwe": "CWE-798",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14866"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-66016",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.00242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-312",
      "title": "Rendered Artifactory Helm manifests may contain generated TLS private keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66016"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-48791",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00056,
      "epss_percentile": 0.00004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sigstore",
      "product": "sigstore-java",
      "cwe": "CWE-347",
      "title": "Sigstore Java has a vulnerability with bundle verification of integratedTime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48791"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-10271",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-10271 (Oracle Corporation WebLogic Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-11138",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-11138. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-15982",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-15982. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-20250",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-20250 (Check Point Software Technologies Ltd. WinRAR). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-7602",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-7602 (Drupal core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-8120",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-8120 (Microsoft Windows Server 2008). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-8174",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-8174 (Microsoft Windows 7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-0752",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-0752 (Microsoft Internet Explorer 11). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-1069",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-1069 (Microsoft Windows 10 Version 1703). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-1458",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-1458 (Microsoft Windows). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-1579",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-1579 (Palo Alto Networks GlobalProtect Portal/Gateway Interface). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-0787",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-0787 (Microsoft Windows). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-0796",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-0796 (Microsoft Windows 10 Version 1903 for 32-bit Systems). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-3153",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-3153 (Cisco AnyConnect Secure Mobility Client). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-3433",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-3433 (Cisco AnyConnect Secure Mobility Client). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-1675",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-1675 (Microsoft Windows 10 Version 1809). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-1732",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-1732 (Microsoft Windows 10 Version 1803). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21972",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21972 (VMware vCenter Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21975",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21975 (VMware vRealize Operations). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21983",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21983 (VMware vRealize Operations). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-21985",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-21985 (VMware vCenter Server and VMware Cloud Foundation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-26855",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-26855 (Microsoft Exchange Server 2016 Cumulative Update 19). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-27065",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-27065 (Microsoft Exchange Server 2019). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-42787",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-42787 (Fortinet FortiAnalyzer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-14042",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-14042 (Open5GS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10681",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10681 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14548",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14548 (Unknown Ray Enterprise Translation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14549",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14549 (Unknown Ray Enterprise Translation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17022",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17022 (Unknown Salon Booking System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19351",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19351 (dresende node-sql-query). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19361",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19361 (macrozheng mall). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19376",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19376 (Uasoft Badaso). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19382",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19382 (Almico Speedfan). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45799",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45799 (square wire). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5241 (huggingface/transformers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67579 (ash-project ash). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2019-2725",
      "detail": "RESCORED — CVE-2019-2725 (Oracle Corporation Tape Library ACSLS). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-42787",
      "detail": "RESCORED — CVE-2023-42787 (Fortinet FortiAnalyzer). CVSS 6.2 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-14043",
      "detail": "RESCORED — CVE-2024-14043 (Open5GS). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-26882",
      "detail": "RESCORED — CVE-2024-26882 (Linux). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-31245",
      "detail": "RESCORED — CVE-2024-31245 (ConvertKit). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-31249",
      "detail": "RESCORED — CVE-2024-31249 (WPKube Subscribe To Comments Reloaded). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-61848",
      "detail": "RESCORED — CVE-2025-61848 (Fortinet FortiManager). CVSS 6.5 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49261",
      "detail": "RESCORED — CVE-2026-49261 (MariaDB server). CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4942",
      "detail": "RESCORED — CVE-2026-4942 (IBM i). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50656",
      "detail": "RESCORED — CVE-2026-50656 (Microsoft Malware Protection Engine). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-5241",
      "detail": "RESCORED — CVE-2026-5241 (huggingface/transformers). CVSS 8 → 9.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55653",
      "detail": "RESCORED — CVE-2026-55653 (Red Hat Enterprise Linux 10). CVSS 4.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55655",
      "detail": "RESCORED — CVE-2026-55655 (Red Hat Enterprise Linux 10). CVSS 5 → 6.1 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2018-9206",
      "detail": "ENRICHED — CVE-2018-9206 (Blueimp jQuery-File-Upload). Received CVSS 9.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-21983",
      "detail": "ENRICHED — CVE-2021-21983 (VMware vRealize Operations). Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-50073",
      "detail": "ENRICHED — CVE-2022-50073 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
