{
  "day": "2026-08-13",
  "boundary": "UTC calendar day",
  "published_count": 606,
  "by_severity": {
    "CRITICAL": 80,
    "HIGH": 263,
    "MEDIUM": 233,
    "LOW": 29
  },
  "kev_count": 0,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-19747",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02364,
      "epss_percentile": 0.82435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH7",
      "cwe": "CWE-74",
      "title": "Tenda CH7 ATE Module Kylin HandleCmd command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19747"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-11840",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01583,
      "epss_percentile": 0.73568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Password Manager Pro",
      "cwe": "CWE-89",
      "title": "SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11840"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-73663",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00954,
      "epss_percentile": 0.58595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "missedcall",
      "cwe": "CWE-89",
      "title": "FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73663"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-72776",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00838,
      "epss_percentile": 0.54967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fosowl",
      "product": "AgenticSeek",
      "cwe": "CWE-306",
      "title": "AgenticSeek Unauthenticated RCE via /query API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72776"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-12263",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00696,
      "epss_percentile": 0.50198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Password Manager Pro",
      "cwe": "CWE-347",
      "title": "Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12263"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-73623",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00692,
      "epss_percentile": 0.5006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-78",
      "title": "GitPython before 3.1.54 Remote Code Execution via --template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73623"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-18428",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.49968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Opensearch",
      "cwe": "CWE-693",
      "title": "SQL Query Validation Bypass in OpenSearch Direct Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18428"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-73662",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00659,
      "epss_percentile": 0.4877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "music",
      "cwe": "CWE-78",
      "title": "Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73662"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-14662",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00655,
      "epss_percentile": 0.48623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-190",
      "title": "PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14662"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-73664",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00653,
      "epss_percentile": 0.48535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "backup",
      "cwe": "CWE-269",
      "title": "FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73664"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-73653",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00644,
      "epss_percentile": 0.481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vitest-dev",
      "product": "vitest",
      "cwe": "CWE-22",
      "title": "Vitest: Browser Mode provider commands bypass the file-access permission gate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73653"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-73421",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00644,
      "epss_percentile": 0.48096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextauthjs",
      "product": "next-auth",
      "cwe": "CWE-285",
      "title": "NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73421"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-73667",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00615,
      "epss_percentile": 0.46802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openchoreo",
      "product": "openchoreo",
      "cwe": "CWE-78",
      "title": "OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73667"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-14676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00609,
      "epss_percentile": 0.46493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-122",
      "title": "PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14676"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-73601",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00606,
      "epss_percentile": 0.46357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-95",
      "title": "Flowise before 3.1.3 Remote Code Execution via Custom MCP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73601"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-14677",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00604,
      "epss_percentile": 0.46254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-190",
      "title": "PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14677"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-14680",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00604,
      "epss_percentile": 0.46255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-843",
      "title": "PostgreSQL type confusion via \"internal\" arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14680"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-14664",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-122",
      "title": "PostgreSQL regexp heap buffer overflow executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14664"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-14669",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-122",
      "title": "PostgreSQL to_char heap buffer overflow executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14669"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-14670",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-122",
      "title": "PostgreSQL plperl tied object heap buffer overflow executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14670"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-19385",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-122",
      "title": "PostgreSQL pg_dump heap buffer overflow executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19385"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-16238",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0059,
      "epss_percentile": 0.45654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-843",
      "title": "PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16238"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-16239",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0059,
      "epss_percentile": 0.45654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-843",
      "title": "PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16239"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-56853",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0059,
      "epss_percentile": 0.45649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "net/http",
      "cwe": "CWE-770",
      "title": "Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-27544",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00589,
      "epss_percentile": 0.45586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuarkA",
      "product": "QA Analytics",
      "cwe": "CWE-94",
      "title": "WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27544"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2019-25765",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00588,
      "epss_percentile": 0.45541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASP-CMS Project",
      "product": "ASP-CMS",
      "cwe": "CWE-89",
      "title": "ASP-CMS SQL Injection via commentList.asp id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25765"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-53795",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00581,
      "epss_percentile": 0.45201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53795"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-58443",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00578,
      "epss_percentile": 0.45057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-863",
      "title": "Public-only repository tokens can update private PR head branches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58443"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-70464",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00573,
      "epss_percentile": 0.44826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-770",
      "title": "rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70464"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-17481",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00571,
      "epss_percentile": 0.4471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Documentation Offline",
      "cwe": "CWE-117",
      "title": "IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17481"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-67614",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00552,
      "epss_percentile": 0.43784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-798",
      "title": "CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67614"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-73417",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-79",
      "title": "JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73417"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-14525",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00551,
      "epss_percentile": 0.43687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-306",
      "title": "IBM WebSphere Application Server Liberty is affected by an authenication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14525"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-17482",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00545,
      "epss_percentile": 0.43382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Documentation Offline",
      "cwe": "CWE-73",
      "title": "IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17482"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-73570",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Collaboration",
      "cwe": "CWE-78",
      "title": "A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73570"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-10571",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00529,
      "epss_percentile": 0.42495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-502",
      "title": "IBM WebSphere Application Server Liberty is affected by a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10571"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-73420",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00528,
      "epss_percentile": 0.42476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextauthjs",
      "product": "next-auth",
      "cwe": "CWE-180",
      "title": "NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73420"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-16975",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By A Remote Code Execution Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16975"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-18408",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-829",
      "title": "PostgreSQL psql \\unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18408"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-70453",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-407",
      "title": "rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70453"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-66256",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shindig Common",
      "cwe": "CWE-502",
      "title": "Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66256"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-53790",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00515,
      "epss_percentile": 0.41683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-78",
      "title": "rsync < 3.5.0 Command Injection via Multiple Code Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53790"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-6471",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00513,
      "epss_percentile": 0.41534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-862",
      "title": "PostgreSQL logical decoding can dlopen arbitrary file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6471"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-70461",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00509,
      "epss_percentile": 0.4131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-787",
      "title": "rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70461"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-73625",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-78",
      "title": "GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73625"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-73649",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00501,
      "epss_percentile": 0.40807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shepherdwind",
      "product": "velocity.js",
      "cwe": "CWE-94",
      "title": "Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73649"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-6464",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00492,
      "epss_percentile": 0.40271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-829",
      "title": "PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6464"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-73416",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00487,
      "epss_percentile": 0.39997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-178",
      "title": "jupyterlab: PyPI extension blocklist package-name canonicalization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73416"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-56859",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.39747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "encoding/xml",
      "cwe": "CWE-770",
      "title": "Add recursion depth guard during decode in encoding/xml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-56862",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.39746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "crypto/tls",
      "cwe": "CWE-770",
      "title": "Limit handshake messages we are willing to accept post-handshake in crypto/tls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2022-4993",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00481,
      "epss_percentile": 0.39621,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "HTML-FormHandler",
      "cwe": "CWE-470",
      "title": "HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-4993"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-73666",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openchoreo",
      "product": "backstage-plugins",
      "cwe": "CWE-306",
      "title": "OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73666"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-49827",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SMEWebify",
      "product": "WebErpMesv2",
      "cwe": "CWE-20",
      "title": "WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49827"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-15742",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-190",
      "title": "PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15742"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-70455",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-770",
      "title": "rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70455"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-59714",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00478,
      "epss_percentile": 0.39434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-862",
      "title": "Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59714"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-61962",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hakan Ozevin",
      "product": "WP BASE Booking",
      "cwe": "CWE-94",
      "title": "WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61962"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2024-58374",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.39245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hongjing Century",
      "product": "e-HR",
      "cwe": "CWE-89",
      "title": "Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58374"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-13048",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.39246,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Data-MuForm",
      "cwe": "CWE-22",
      "title": "Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13048"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-19750",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00474,
      "epss_percentile": 0.3916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH",
      "cwe": "CWE-255",
      "title": "Tenda CH/CP/TX3 SSH hard-coded password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19750"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-19484",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.38994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/busboy",
      "product": "@fastify/busboy",
      "cwe": "CWE-835",
      "title": "@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19484"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-53791",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-290",
      "title": "rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53791"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-14456",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-770",
      "title": "Unbounded Memory Growth in QUIC Server Incoming Channel Queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14456"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-33818",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "encoding/asn1",
      "cwe": "CWE-400",
      "title": "Enforce maximum recursion depth in encoding/asn1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-73532",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00463,
      "epss_percentile": 0.38442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Fluent Forms Pro",
      "cwe": "CWE-506",
      "title": "Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73532"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-70452",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-636",
      "title": "rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70452"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-17473",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Documentation Offline",
      "cwe": "CWE-22",
      "title": "IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17473"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-48702",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sigstore",
      "product": "rekor",
      "cwe": "CWE-770",
      "title": "Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48702"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-73507",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73507"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-14668",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-843",
      "title": "PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14668"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-13051",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00451,
      "epss_percentile": 0.37632,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Form-Processor",
      "cwe": "CWE-470",
      "title": "Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13051"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-73533",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Ninja Tables Pro",
      "cwe": "CWE-506",
      "title": "Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73533"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-70460",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.3742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-22",
      "title": "rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70460"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-73514",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PostGIS",
      "product": "address_standardizer",
      "cwe": "CWE-787",
      "title": "PostGIS address_standardizer Out-of-Bounds Write via standardize_address()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73514"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-73660",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "tts",
      "cwe": "CWE-78",
      "title": "FreePBX: Authenticated TTS AGI Command Injection Through TTS Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73660"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-56860",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.36889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "net/url",
      "cwe": "CWE-407",
      "title": "Avoid quadratic complexity in resolvePath in net/url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-73602",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-95",
      "title": "Flowise before 3.1.3 Sandbox Escape to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73602"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-19487",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00434,
      "epss_percentile": 0.36366,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "perl",
      "cwe": "CWE-670",
      "title": "Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19487"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-73561",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anephenix",
      "product": "hub",
      "cwe": "CWE-400",
      "title": "Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73561"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-17223",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00427,
      "epss_percentile": 0.35825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17223"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-65582",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LiquidThemes",
      "product": "AI Hub",
      "cwe": "CWE-22",
      "title": "WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65582"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-19757",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00424,
      "epss_percentile": 0.35607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-22",
      "title": "Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19757"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-19758",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00424,
      "epss_percentile": 0.35607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-22",
      "title": "dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19758"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-72841",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-73",
      "title": "luci-app-openvpn Path Traversal RCE via instance_name2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72841"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-72842",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-73",
      "title": "OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72842"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-72850",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-22",
      "title": "Budibase before 3.40.0 Arbitrary File Write via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72850"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-19297",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00418,
      "epss_percentile": 0.35042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-307",
      "title": "Insufficient Authentication Brute Force Protection on Login Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19297"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-16674",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-426",
      "title": "IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16674"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-73515",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PostGIS",
      "product": "PostGIS",
      "cwe": "CWE-125",
      "title": "PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73515"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-16867",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-287",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16867"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-56654",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.34258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Privilege Escalation via Access Token Scope Escalation in API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56654"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-15741",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-89",
      "title": "PostgreSQL expression deparse allows SQL injection via EXTRACT argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15741"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-17101",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00406,
      "epss_percentile": 0.33978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-287",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17101"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-14671",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-843",
      "title": "PostgreSQL refint plan cache type confusion executes arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14671"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-16908",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Multiple SQL Vulnerabilities [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16908"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-28008",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.3381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "OAuth Single Sign On – SSO (OAuth Client)",
      "cwe": "CWE-290",
      "title": "WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28008"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-66453",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.33811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dimitri Grassi",
      "product": "Salon booking system",
      "cwe": "CWE-288",
      "title": "WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66453"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-66465",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.33811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AgniHD",
      "product": "Cartify",
      "cwe": "CWE-288",
      "title": "WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66465"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-19749",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00402,
      "epss_percentile": 0.33605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH7",
      "cwe": "CWE-287",
      "title": "Tenda CH7 RTSP/ONVIF missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19749"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-14679",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-121",
      "title": "PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14679"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-19761",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00399,
      "epss_percentile": 0.33345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DTStack",
      "product": "Taier",
      "cwe": "CWE-22",
      "title": "DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19761"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-59503",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-200",
      "title": "Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59503"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-59504",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.3315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-602",
      "title": "Priority – CWE-602: Client-Side Enforcement of Server-Side Security",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59504"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-73670",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saurus",
      "product": "Saurus CMS Community Edition",
      "cwe": "CWE-89",
      "title": "CMS Admin SQL Injection via db_data.php table_name Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73670"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-66432",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denishua",
      "product": "WPJAM Basic",
      "cwe": "CWE-1258",
      "title": "WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66432"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-66443",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pete Nelson",
      "product": "REST API Log",
      "cwe": "CWE-201",
      "title": "WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66443"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-70456",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-787",
      "title": "rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70456"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-70458",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-787",
      "title": "rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70458"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-73648",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.32922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rails",
      "product": "rails-html-sanitizer",
      "cwe": "CWE-79",
      "title": "rails-html-sanitizer: Possible XSS vulnerability with certain configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73648"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-59506",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00395,
      "epss_percentile": 0.32896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-306",
      "title": "Priority – CWE-306: Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59506"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-72839",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00394,
      "epss_percentile": 0.327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-266",
      "title": "filebrowser through 2.63.16 Privilege Escalation via Signup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72839"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-14672",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-204",
      "title": "PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14672"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-53793",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53793"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-17220",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-120",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17220"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-16982",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16982"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-18846",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18846"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-73487",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00389,
      "epss_percentile": 0.32234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-94",
      "title": "Flowise before 3.1.3 Prompt Injection RCE via CSV Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73487"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-28161",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aonetheme",
      "product": "Service Finder Booking",
      "cwe": "CWE-266",
      "title": "WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28161"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-67613",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.32269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-22",
      "title": "CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67613"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-73559",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-400",
      "title": "vLLM: Completion prompt lists fan out into unbounded engine requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73559"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-73565",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "node-server",
      "cwe": "CWE-401",
      "title": "@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73565"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-28149",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "Headless Single Sign On",
      "cwe": "CWE-502",
      "title": "WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28149"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-16887",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By A Denial of Service Vulnerability DST/SST []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16887"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-17004",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-835",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17004"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-17199",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-770",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17199"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-17229",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-835",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17229"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-73564",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fatedier",
      "product": "frp",
      "cwe": "CWE-129",
      "title": "frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73564"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-73645",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenZeppelin",
      "product": "openzeppelin-confidential-contracts",
      "cwe": "CWE-190",
      "title": "OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73645"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-61966",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denishua",
      "product": "WPJAM Basic",
      "cwe": "CWE-89",
      "title": "WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61966"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-66446",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "If-So Dynamic Content",
      "product": "If-So Dynamic Content Personalization",
      "cwe": "CWE-89",
      "title": "WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66446"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-70459",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-908",
      "title": "rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70459"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-59500",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-287",
      "title": "Priority - CWE-287: Improper Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59500"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-17206",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17206"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-28157",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lasso Analytics, Inc.",
      "product": "Do Lasso",
      "cwe": "CWE-35",
      "title": "WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28157"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-73566",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isaacs",
      "product": "node-tar",
      "cwe": "CWE-400",
      "title": "node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73566"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-59505",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-284",
      "title": "Priority - CWE-284: Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59505"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-66441",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MultiVendorX",
      "product": "MultiVendorX",
      "cwe": "CWE-862",
      "title": "WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66441"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-42931",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.3091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-770",
      "title": "Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42931"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-73483",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-78",
      "title": "Flowise before 3.1.3 Sandbox Escape via Puppeteer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73483"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-53783",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53783"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-61980",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.3057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daan.dev",
      "product": "OMGF Pro",
      "cwe": "CWE-22",
      "title": "WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61980"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-73509",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenListTeam",
      "product": "OpenList",
      "cwe": "CWE-22",
      "title": "OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73509"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-53794",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-1284",
      "title": "rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53794"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-73569",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NaturalIntelligence",
      "product": "fast-xml-parser",
      "cwe": "CWE-776",
      "title": "fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73569"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-45774",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oscal-compass",
      "product": "compliance-trestle",
      "cwe": "CWE-22",
      "title": "compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45774"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-45819",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "web-platform-dx",
      "product": "baseline-browser-mapping",
      "cwe": "CWE-705",
      "title": "baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45819"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-27380",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Car Rental Manager",
      "cwe": "CWE-502",
      "title": "WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27380"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-73562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.30078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Automattic",
      "product": "mongoose",
      "cwe": "CWE-1321",
      "title": "Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73562"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-55982",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00368,
      "epss_percentile": 0.30051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55982"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-73305",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.3006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-269",
      "title": "Budibase: Privilege escalation via public role assignment API missing app-level authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73305"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-73669",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.30043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Signify",
      "product": "Philips Hue Bridge Pro",
      "cwe": "CWE-306",
      "title": "Signify Philips Hue Bridge Pro MQTT broker missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73669"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-58420",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00365,
      "epss_percentile": 0.29749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Local File Inclusion via file:// URI in Migration Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58420"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-73615",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-436",
      "title": "Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73615"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-73613",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-59",
      "title": "filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73613"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-56443",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-863",
      "title": "Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56443"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-73655",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-287",
      "title": "Trigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Google Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73655"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-70457",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-131",
      "title": "rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70457"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-67991",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1333",
      "title": "crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67991"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-17088",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17088"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-72660",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-248",
      "title": "Uncaught Exception in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72660"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-72683",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72683"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-72686",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72686"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-73614",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-436",
      "title": "Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73614"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-19744",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maalfer",
      "product": "Pentestify",
      "cwe": "CWE-79",
      "title": "Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19744"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-72676",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.2892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Fleet Server",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code in Fleet Server Leading to Code Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72676"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-16861",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16861"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-17076",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-770",
      "title": "IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17076"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-17077",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-457",
      "title": "IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17077"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-17078",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-400",
      "title": "IBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17078"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-17212",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17212"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-17216",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-190",
      "title": "IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17216"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-18146",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmanageninja",
      "product": "Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder",
      "cwe": "CWE-79",
      "title": "Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18146"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-73304",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-200",
      "title": "Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73304"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-66444",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kendysond",
      "product": "Payment Forms for Paystack",
      "cwe": "CWE-497",
      "title": "WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66444"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-73841",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openchoreo",
      "product": "openchoreo",
      "cwe": "CWE-639",
      "title": "OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73841"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-16868",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-908",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16868"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-28186",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefic",
      "product": "Travelfic Toolkit",
      "cwe": "CWE-862",
      "title": "WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28186"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-28159",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aonetheme",
      "product": "Service Finder Booking",
      "cwe": "CWE-862",
      "title": "WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28159"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-17043",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00352,
      "epss_percentile": 0.28427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17043"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-73568",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "py-libp2p",
      "cwe": "CWE-400",
      "title": "py-libp2p: yamux connection DoS via oversized data frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73568"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-66450",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dylan Kuhn",
      "product": "Geo Mashup",
      "cwe": "CWE-98",
      "title": "WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66450"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-66653",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Barista",
      "cwe": "CWE-98",
      "title": "WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66653"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-66656",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Foton Core",
      "cwe": "CWE-98",
      "title": "WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66656"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-66657",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Biagiotti Core",
      "cwe": "CWE-98",
      "title": "WordPress Biagiotti Core plugin <= 2.1.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66657"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-49857",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ymw0407",
      "product": "auth-fetch-mcp",
      "cwe": "CWE-918",
      "title": "auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49857"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-58429",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.27767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58429"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-19745",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00345,
      "epss_percentile": 0.27653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Calix",
      "product": "GigaSpire",
      "cwe": "CWE-404",
      "title": "Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19745"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-19746",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00345,
      "epss_percentile": 0.27652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Calix",
      "product": "GigaSpire",
      "cwe": "CWE-404",
      "title": "Calix GigaSpire traceroute.cmd denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19746"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-70463",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-863",
      "title": "rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70463"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-73659",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-22",
      "title": "Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73659"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-73643",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodeca",
      "product": "js-yaml",
      "cwe": "CWE-407",
      "title": "js-yaml: Exponential parsing time in the flow collections leads to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73643"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-19716",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maalfer",
      "product": "Pentestify",
      "cwe": "CWE-79",
      "title": "Stored Cross-site Scripting in Pentestify user account deletion via unescaped username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19716"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-73656",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-639",
      "title": "Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73656"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-56750",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Gitea Remember-Me Token Theft Not Invalidating Attacker Session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56750"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-28156",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lasso Analytics, Inc.",
      "product": "Do Lasso",
      "cwe": "CWE-89",
      "title": "WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28156"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-28168",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.2736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imran Tauqeer",
      "product": "CubeWP",
      "cwe": "CWE-89",
      "title": "WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28168"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-66430",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODEPRESS",
      "product": "Visitor Traffic Real Time Statistics Pro",
      "cwe": "CWE-89",
      "title": "WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66430"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-66658",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MVPThemes",
      "product": "Reviewer",
      "cwe": "CWE-89",
      "title": "WordPress Reviewer plugin <= 3.14.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66658"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-17272",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By a Denial of Service in HTTP Server []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17272"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-58417",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "REST API exposes organization membership of private organizations to public",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58417"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-58427",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "Private org member list leaked via /members API endpoint — incomplete fix for PR #38145",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58427"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-17197",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0034,
      "epss_percentile": 0.27082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-287",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17197"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-55984",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.26616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55984"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-73661",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "framework",
      "cwe": "CWE-15",
      "title": "FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73661"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-58436",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-407",
      "title": "ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58436"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-16241",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00335,
      "epss_percentile": 0.26579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-191",
      "title": "PostgreSQL ECPG integer underflow can crash the client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16241"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-73654",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-1321",
      "title": "Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73654"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-73508",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.2631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-772",
      "title": "Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73508"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-73658",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-20",
      "title": "Trigger.dev: Cross-tenant object store read and write via URL path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73658"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-61967",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.2608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "miniorange otp verification",
      "cwe": "CWE-640",
      "title": "WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61967"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-66424",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozy Vision Technologies Pvt. Ltd.",
      "product": "SMS Alert Order Notifications",
      "cwe": "CWE-266",
      "title": "WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66424"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-66691",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriptsbundle",
      "product": "Nokri",
      "cwe": "CWE-640",
      "title": "WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66691"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-73620",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-22",
      "title": "GitPython before 3.1.57 Arbitrary File Overwrite and Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73620"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-48099",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mar10",
      "product": "wsgidav",
      "cwe": "CWE-22",
      "title": "WsgiDAV encoded dot segments can escape filesystem share roots",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48099"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-58428",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-424",
      "title": "Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58428"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-73408",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-89",
      "title": "Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73408"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-16929",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Host Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16929"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-6470",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-862",
      "title": "PostgreSQL fails to check type USAGE privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6470"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-73486",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-94",
      "title": "Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73486"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-72642",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-823",
      "title": "Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72642"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-19710",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.2581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Student Information System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Student Information System view_department.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19710"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-19734",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19734"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-72856",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-640",
      "title": "Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72856"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-16853",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16853"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-17099",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.2554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-287",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17099"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-27999",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefic",
      "product": "Tourfic",
      "cwe": "CWE-862",
      "title": "WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27999"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-28181",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "AcyMailing SMTP Newsletter",
      "cwe": "CWE-862",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28181"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-18193",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18193"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-49089",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49089"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-17071",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00325,
      "epss_percentile": 0.25511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17071"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-49864",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "butlerx",
      "product": "wetty",
      "cwe": "CWE-79",
      "title": "wetty vulnerable to DOM XSS via file-download filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49864"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-59499",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions).",
      "cwe": "CWE-200",
      "title": "Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59499"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-59507",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-798",
      "title": "Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59507"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-73567",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.25026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JuneAndGreen",
      "product": "sm-crypto",
      "cwe": "CWE-338",
      "title": "sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73567"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-59501",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-284",
      "title": "Priority – CWE-284: Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59501"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-8715",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00319,
      "epss_percentile": 0.24734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-552",
      "title": "Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8715"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-18077",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18077"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-6469",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.24642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-708",
      "title": "PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6469"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-72777",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DayuanJiang",
      "product": "next-ai-draw-io",
      "cwe": "CWE-918",
      "title": "Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72777"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-73603",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-862",
      "title": "Flowise before 3.1.4 Credential Abuse via Text-to-Speech",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73603"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-59502",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Priority",
      "product": "Portal Generator addon to Priority ERP (developed by Soft Solutions)",
      "cwe": "CWE-203",
      "title": "Priority - CWE-203: Observable Discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59502"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-73556",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-400",
      "title": "vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73556"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-73302",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-287",
      "title": "Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73302"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-0301",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00313,
      "epss_percentile": 0.24139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-908",
      "title": "PAN-OS: Information Disclosure Vulnerability in URL Filtering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0301"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-55402",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-125",
      "title": "CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55402"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-59109",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.2403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zalktis Programmas (SIA \"Zalktis Programmas\")",
      "product": "Zalktis",
      "cwe": "CWE-20",
      "title": "Zalktis: SQL injection via partner-controlled fields in imported e-invoices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59109"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-66661",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.2395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Onokazu",
      "product": "Directories Pro",
      "cwe": "CWE-266",
      "title": "WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66661"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-55401",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.23945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-476",
      "title": "CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55401"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-73530",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flytohub",
      "product": "flyto-core",
      "cwe": "CWE-918",
      "title": "Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73530"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-28176",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Booking Activities Team",
      "product": "Booking Activities",
      "cwe": "CWE-502",
      "title": "WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28176"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-53789",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-807",
      "title": "rsync < 3.5.0 Arbitrary File Deletion via Malicious File List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53789"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-53792",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-129",
      "title": "rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53792"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-16961",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00309,
      "epss_percentile": 0.23626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-89",
      "title": "IBM i is Affected By SQL Injection Vulnerability in Db2 Mirror []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16961"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-19748",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00308,
      "epss_percentile": 0.23518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH7",
      "cwe": "CWE-330",
      "title": "Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19748"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-27535",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "solacewp",
      "product": "Solace Extra",
      "cwe": "CWE-862",
      "title": "WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27535"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-17075",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-287",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17075"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-73647",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quasarframework",
      "product": "quasar",
      "cwe": "CWE-1321",
      "title": "Quasar Framework: Prototype pollution in Quasar extend() utility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73647"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-17502",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17502"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-72670",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-200",
      "title": "Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72670"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-24059",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-269",
      "title": "Gitea runner registration-token GET endpoint performs a write under a read-only token scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24059"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-14182",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Customer Email Verification for WooCommerce",
      "cwe": "CWE-287",
      "title": "Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14182"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-72840",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-266",
      "title": "OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72840"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-66462",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BookingWP",
      "product": "WooCommerce Appointments",
      "cwe": "CWE-497",
      "title": "WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66462"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-66463",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hassan Fakih",
      "product": "iCARRY",
      "cwe": "CWE-201",
      "title": "WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66463"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-17045",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.2285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-294",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17045"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-59765",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-918",
      "title": "SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59765"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-14678",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-126",
      "title": "PostgreSQL pg_trgm picksplit reads past end of buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14678"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-28189",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roland Barker",
      "product": "Participants Database",
      "cwe": "CWE-22",
      "title": "WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28189"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-57897",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57897"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-16878",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16878"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-73665",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "ucp",
      "cwe": "CWE-862",
      "title": "FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73665"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-55987",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-863",
      "title": "OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55987"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-58314",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-918",
      "title": "Two SSRF findings in Gitea 1.26.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58314"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-17226",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17226"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-18024",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-126",
      "title": "PostgreSQL ascii() function reads past end of buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18024"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-73644",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.22039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenDJ",
      "cwe": "CWE-285",
      "title": "OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73644"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-72636",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72636"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-16859",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16859"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-72629",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.2181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72629"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-73843",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openchoreo",
      "product": "openchoreo",
      "cwe": "CWE-306",
      "title": "OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73843"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-28001",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDirectoryKit",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28001"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-28142",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shamalli",
      "product": "Web Directory Free",
      "cwe": "CWE-89",
      "title": "WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28142"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-61969",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webilia Inc.",
      "product": "Listdom",
      "cwe": "CWE-89",
      "title": "WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61969"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-66436",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "Active Products Tables for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66436"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-66458",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "RealPress",
      "cwe": "CWE-89",
      "title": "WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66458"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-66472",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "everestthemes",
      "product": "Everest Backup",
      "cwe": "CWE-89",
      "title": "WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66472"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-66478",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andy_moyle",
      "product": "Church Admin",
      "cwe": "CWE-89",
      "title": "WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66478"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-16692",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16692"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-49820",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getprobo",
      "product": "probo",
      "cwe": "CWE-601",
      "title": "Probo has an open redirect bypass via path normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49820"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-15413",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.2158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Link Factory",
      "cwe": "CWE-912",
      "title": "Link Factory - Backdoor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15413"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-73618",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-943",
      "title": "Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73618"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-73484",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.2149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-184",
      "title": "Flowise before 3.1.3 Sandbox Escape via Pandas Methods",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73484"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-72638",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72638"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-72639",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-789",
      "title": "Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72639"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-72645",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-789",
      "title": "Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72645"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-72647",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72647"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-72651",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72651"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-72653",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72653"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-72656",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-789",
      "title": "Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72656"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-72659",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72659"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-72663",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-407",
      "title": "Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72663"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-72667",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72667"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-72674",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72674"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-72678",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-789",
      "title": "Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72678"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-72679",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72679"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-72684",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72684"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-72687",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-789",
      "title": "Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72687"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-18020",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18020"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-19756",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00288,
      "epss_percentile": 0.21404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-22",
      "title": "Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19756"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-61984",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amauri",
      "product": "WPMobile.App",
      "cwe": "CWE-862",
      "title": "WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61984"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-72851",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00286,
      "epss_percentile": 0.21137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-89",
      "title": "Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72851"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-53801",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Symlink Race Condition Directory Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53801"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-58433",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.20988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-862",
      "title": "Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58433"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-58439",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58439"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-73485",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-94",
      "title": "Flowise before 3.1.3 Remote Code Execution via Airtable Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73485"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-58434",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "Private Repository Metadata Remains Accessible After Access Revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58434"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-49478",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sigstore",
      "product": "fulcio",
      "cwe": "CWE-918",
      "title": "Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49478"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-73622",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-200",
      "title": "GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73622"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-13460",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Storage Scale",
      "cwe": "CWE-798",
      "title": "The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13460"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-73604",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-200",
      "title": "Flowise before 3.1.3 Credential Exposure via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73604"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-73346",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.2043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mailchimp",
      "product": "MailChimp For WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73346"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-66693",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "Motors",
      "cwe": "CWE-862",
      "title": "WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66693"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-19481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/busboy",
      "product": "@fastify/busboy",
      "cwe": "CWE-754",
      "title": "@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19481"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-53798",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-704",
      "title": "rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53798"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-58440",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58440"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-19753",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Model Context Protocol",
      "product": "mcp-rdf-explorer",
      "cwe": "CWE-918",
      "title": "Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19753"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-16722",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16722"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-72666",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72666"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-73624",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-88",
      "title": "GitPython before 3.1.54 Arbitrary File Overwrite via diff",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73624"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-72648",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Eck Operator",
      "cwe": "CWE-526",
      "title": "Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72648"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-72855",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-918",
      "title": "Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72855"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-3835",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "buildwps",
      "product": "Prevent Direct Access – Protect WordPress Files",
      "cwe": "CWE-285",
      "title": "Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3835"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-72677",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-23",
      "title": "Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72677"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-53786",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.1964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-863",
      "title": "rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53786"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-27543",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluxBuilder",
      "product": "MStore API",
      "cwe": "CWE-266",
      "title": "WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27543"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-61979",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "SAML SP Single Sign On",
      "cwe": "CWE-266",
      "title": "WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61979"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-16871",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16871"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-72650",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72650"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-28174",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event SOlution",
      "cwe": "CWE-201",
      "title": "WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28174"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-19751",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.19279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnzoVezzaro",
      "product": "mcp-dominican-layer",
      "cwe": "CWE-918",
      "title": "EnzoVezzaro mcp-dominican-layer parse-csv tool index.ts axios.get server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19751"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-19752",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.19279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnzoVezzaro",
      "product": "mcp-dominican-layer",
      "cwe": "CWE-918",
      "title": "EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19752"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-14673",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00269,
      "epss_percentile": 0.19154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-426",
      "title": "PostgreSQL amcheck does not clear untrusted search path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14673"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-58508",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58508"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-58438",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-862",
      "title": "Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58438"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-45725",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.1906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oscal-compass",
      "product": "compliance-trestle",
      "cwe": "CWE-73",
      "title": "compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45725"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-72657",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Fleet Server",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Fleet Server Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72657"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-58432",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58432"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-57894",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-918",
      "title": "Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57894"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-73612",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-639",
      "title": "File Browser before v2.63.22 Authorization Bypass via Recursive Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73612"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-73611",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.1859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-613",
      "title": "File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73611"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-16815",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16815"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-18249",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.1852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18249"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-73488",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-639",
      "title": "Flowise before 3.1.3 IDOR via customer-default-source endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73488"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-72664",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72664"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-50105",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50105"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-56858",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "html/template",
      "cwe": "CWE-79",
      "title": "Fix Javascript regexp context tracking in html/template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-17476",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17476"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-13610",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "KiviCare",
      "cwe": "CWE-269",
      "title": "KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13610"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-49096",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-248",
      "title": "Uncaught Exception in Kibana Cases Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49096"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-72685",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-407",
      "title": "Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72685"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-17468",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Documentation Offline",
      "cwe": "CWE-321",
      "title": "IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17468"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-73558",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-190",
      "title": "vLLM: Cross-User Data Leak Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73558"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-28002",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "Booktics",
      "cwe": "CWE-89",
      "title": "WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28002"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-70462",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-190",
      "title": "rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70462"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-73489",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-129",
      "title": "Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73489"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-72857",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-522",
      "title": "Budibase before 3.40.0 Credential Exposure via STRING Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72857"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-3639",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "buildwps",
      "product": "PPWP – Password Protect Pages",
      "cwe": "CWE-79",
      "title": "PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3639"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-73555",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-209",
      "title": "vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73555"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-16967",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-367",
      "title": "IBM i is Affected By Multiple SQL Vulnerabilities [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16967"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-72643",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72643"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-73573",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00253,
      "epss_percentile": 0.16998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Collaboration",
      "cwe": "CWE-24",
      "title": "In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73573"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-72665",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.1685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72665"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-58416",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-280",
      "title": "Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58416"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-72661",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.1692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72661"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-72681",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72681"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-57886",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-639",
      "title": "Cross-repository issue/comment attachment re-linking can expose private attachment content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57886"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-16713",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Documentation Offline",
      "cwe": "CWE-1327",
      "title": "IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16713"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-53788",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-93",
      "title": "rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53788"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-73557",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-362",
      "title": "vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73557"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-24791",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-863",
      "title": "Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24791"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-18715",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-611",
      "title": "IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18715"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-73627",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-602",
      "title": "JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73627"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-72672",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72672"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-56864",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go toolchain",
      "product": "cmd/go",
      "cwe": "CWE-347",
      "title": "Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56864"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-72640",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Eck Operator",
      "cwe": "CWE-441",
      "title": "Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72640"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-27538",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDirectoryKit",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27538"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-27345",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Taxi Booking Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27345"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-66431",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WoompaLoompa",
      "product": "Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)",
      "cwe": "CWE-862",
      "title": "WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66431"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-66461",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smepay",
      "product": "SMEPay: UPI Gateway for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66461"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-66466",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart",
      "cwe": "CWE-862",
      "title": "WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66466"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-66469",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Afonso Matos",
      "product": "Arvow AI SEO Writer",
      "cwe": "CWE-862",
      "title": "WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66469"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-72853",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-89",
      "title": "Budibase before 3.40.0 SQL Injection via Oracle connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72853"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-58442",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "Repository migration SSRF via multi-answer DNS allow-list bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58442"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-73482",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phplist",
      "product": "phplist3",
      "cwe": "CWE-352",
      "title": "phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73482"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-58425",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58425"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-73650",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svg",
      "product": "svgo",
      "cwe": "CWE-79",
      "title": "SVGO: removeScripts plugin leaves some executable scripts intact",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73650"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-28155",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lasso Analytics, Inc.",
      "product": "Do Lasso",
      "cwe": "CWE-639",
      "title": "WordPress Do Lasso plugin <= 358 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28155"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-61978",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.1564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webhosting4ugr",
      "product": "Secure Card Gateway for ePay Paycenter (Piraeus Bank)",
      "cwe": "CWE-862",
      "title": "WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61978"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-66454",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Maruti Mohanty",
      "product": "WP Social Avatar",
      "cwe": "CWE-862",
      "title": "WordPress WP Social Avatar plugin <= 1.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66454"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-66459",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.1564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Space Codes",
      "product": "AI for SEO",
      "cwe": "CWE-862",
      "title": "WordPress AI for SEO plugin <= 2.4.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66459"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-66660",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scott Paterson",
      "product": "Contact Form 7 – PayPal & Stripe Add-on",
      "cwe": "CWE-862",
      "title": "WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66660"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-73608",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73608"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-14298",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-409",
      "title": "Denial of service via resource exhaustion in Mattermost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14298"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-17649",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17649"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-28148",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00239,
      "epss_percentile": 0.15295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "Headless Single Sign On",
      "cwe": "CWE-347",
      "title": "WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28148"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-59763",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59763"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-66697",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Colissimo",
      "product": "Colissimo Officiel : Méthodes de livraison pour WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66697"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-58507",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.1498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Private Repository Existence Disclosure via go-get Meta Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58507"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-73840",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openchoreo",
      "product": "openchoreo",
      "cwe": "CWE-287",
      "title": "OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73840"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-72632",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-203",
      "title": "Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72632"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-55986",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Email Management API Bypasses ManageCredentials Feature Restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55986"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-73651",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typeorm",
      "product": "typeorm",
      "cwe": "CWE-94",
      "title": "TypeORM: migration:generate template-literal code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73651"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-18164",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flow Neuroscience",
      "product": "FL-100",
      "cwe": "CWE-798",
      "title": "Flow Neuroscience FL-100 Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18164"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-23603",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.13957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-918",
      "title": "Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23603"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-55400",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-190",
      "title": "CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55400"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-73353",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "revolutbusiness",
      "product": "Revolut Gateway for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73353"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-19292",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "WiseConnect",
      "cwe": "CWE-305",
      "title": "Bluetooth re-pairing with legitimate device can use lower security level",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19292"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-73619",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-73",
      "title": "GitPython before 3.1.57 Arbitrary File Read via Repo.archive()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73619"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-28173",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event SOlution",
      "cwe": "CWE-862",
      "title": "WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28173"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-58511",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "Webhook Authorization Header Returned in Plaintext via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58511"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-73039",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "streamaserver",
      "product": "streama",
      "cwe": "CWE-639",
      "title": "streama Insecure Direct Object Reference via ViewingStatusController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73039"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-73671",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saurus",
      "product": "Saurus CMS Community Edition",
      "cwe": "CWE-601",
      "title": "Saurus CMS Unauthenticated Open Redirect via logout url parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73671"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-17074",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.1318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17074"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-72669",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.1311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72669"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-58444",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-863",
      "title": "Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58444"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-28188",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefic",
      "product": "Hydra Booking",
      "cwe": "CWE-862",
      "title": "WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28188"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-72655",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-915",
      "title": "Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72655"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-72675",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72675"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-18068",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-200",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18068"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-21832",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "AION",
      "cwe": "CWE-1427",
      "title": "HCL AION is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21832"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-73349",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-862",
      "title": "WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73349"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-73401",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InstaWP",
      "product": "InstaWP Connect",
      "cwe": "CWE-862",
      "title": "WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73401"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-73403",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.1206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "User Registration",
      "cwe": "CWE-862",
      "title": "WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73403"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-58445",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-203",
      "title": "Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58445"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-72631",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-269",
      "title": "Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72631"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-72680",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.1183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72680"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-16101",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "WiseConnect",
      "cwe": "CWE-290",
      "title": "forced re-pairing with already bonded device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16101"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-19291",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "WiseConnect",
      "cwe": "CWE-290",
      "title": "Bluetooth re-pairing can use a lower security level than previous",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19291"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-72630",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72630"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-28182",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "AcyMailing SMTP Newsletter",
      "cwe": "CWE-79",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28182"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-66456",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestwebsoft",
      "product": "Profile Extra Fields by BestWebSoft",
      "cwe": "CWE-79",
      "title": "WordPress Profile Extra Fields by BestWebSoft plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66456"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-66460",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AfterShip & Automizely",
      "product": "AfterShip Tracking",
      "cwe": "CWE-79",
      "title": "WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66460"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-66467",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "FluentCommunity",
      "cwe": "CWE-79",
      "title": "WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66467"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-66471",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themepoints",
      "product": "Accordion",
      "cwe": "CWE-79",
      "title": "WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66471"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-18671",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-190",
      "title": "IBM i is Affected By Multiple Vulnerabilities in NetServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18671"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-54481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-295",
      "title": "Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54481"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-72673",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72673"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-49856",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vmoranv",
      "product": "jshookmcp",
      "cwe": "CWE-918",
      "title": "@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49856"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-73652",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vantage6",
      "product": "vantage6",
      "cwe": "CWE-863",
      "title": "vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73652"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-73531",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-helpdesk",
      "product": "django-helpdesk",
      "cwe": "CWE-79",
      "title": "django-helpdesk < 2.3.3 Stored XSS via HTML Attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73531"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-14666",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-1250",
      "title": "PostgreSQL row security caching disregards role modifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14666"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-73617",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-943",
      "title": "Budibase before 3.40.0 NoSQL Injection via MongoDB datasource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73617"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-73610",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-639",
      "title": "SiYuan before v3.7.4 Information Disclosure via Local Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73610"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-73563",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-601",
      "title": "Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73563"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-73574",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Collaboration",
      "cwe": "CWE-669",
      "title": "In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73574"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-13328",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Food Menu",
      "cwe": "CWE-284",
      "title": "TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13328"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-73621",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-88",
      "title": "GitPython before 3.1.56 Arbitrary File Truncation via Commit.count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73621"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-28185",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00198,
      "epss_percentile": 0.10011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtCamp",
      "product": "Log in with Google",
      "cwe": "CWE-345",
      "title": "WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28185"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-18728",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-191",
      "title": "Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18728"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-66455",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rockiger",
      "product": "ReactPress",
      "cwe": "CWE-862",
      "title": "WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66455"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-66654",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TangibleWP",
      "product": "Vehica Core",
      "cwe": "CWE-918",
      "title": "WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66654"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-16455",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teltonika Networks",
      "product": "RUTOS",
      "cwe": "CWE-93",
      "title": "Local privilege escalation via improper input sanitization in execl() call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16455"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-66704",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jegstudio",
      "product": "Gutenverse Companion",
      "cwe": "CWE-918",
      "title": "WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66704"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-73605",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Path Traversal via getUniqueFilename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73605"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-73606",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-639",
      "title": "SiYuan before v3.7.4 Information Disclosure via getRefIDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73606"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-73607",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getOutlineStorage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73607"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-73609",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getBookmarkLabels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73609"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-66464",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toast Plugins",
      "product": "Internal Link Optimiser",
      "cwe": "CWE-862",
      "title": "WordPress Internal Link Optimiser plugin <= 5.2.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66464"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-73038",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.0943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NodeBB",
      "product": "NodeBB",
      "cwe": "CWE-79",
      "title": "NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73038"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-18945",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Helper Premium",
      "cwe": "CWE-639",
      "title": "WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18945"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-58437",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Repository Visibility Manipulation via Git Push Options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58437"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-0299",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "GlobalProtect App",
      "cwe": "CWE-426",
      "title": "GlobalProtect App: Local Privilege Escalation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0299"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-58431",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-863",
      "title": "Public-only API token restriction is not enforced on team API routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58431"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-58510",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-200",
      "title": "GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58510"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-67986",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67986"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-70454",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-295",
      "title": "rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70454"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-72741",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goodrain",
      "product": "rainbond",
      "cwe": "CWE-639",
      "title": "Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72741"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-73629",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "s9y",
      "product": "Serendipity",
      "cwe": "CWE-918",
      "title": "Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73629"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-66689",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "Anti Spam and list cleaner &#8211; AcyChecker",
      "cwe": "CWE-862",
      "title": "WordPress Anti Spam and list cleaner – AcyChecker plugin <= 2.0.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66689"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-73576",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Collaboration",
      "cwe": "CWE-1241",
      "title": "In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73576"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-0298",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "GlobalProtect App",
      "cwe": "CWE-94",
      "title": "GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0298"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-28154",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "snstheme",
      "product": "Samex - Clean, Minimal Shop WooCommerce WordPress Theme",
      "cwe": "CWE-79",
      "title": "WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28154"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-72671",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72671"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-73616",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openremote",
      "product": "openremote",
      "cwe": "CWE-639",
      "title": "OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73616"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-73626",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00181,
      "epss_percentile": 0.08016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab",
      "cwe": "CWE-284",
      "title": "JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73626"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-73842",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0018,
      "epss_percentile": 0.07836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openchoreo",
      "product": "openchoreo",
      "cwe": "CWE-269",
      "title": "OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73842"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-27536",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PluginOps",
      "product": "MailChimp Subscribe Forms",
      "cwe": "CWE-79",
      "title": "WordPress MailChimp Subscribe Forms plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27536"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-27539",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Welcart",
      "product": "Welcart e-Commerce",
      "cwe": "CWE-79",
      "title": "WordPress Welcart e-Commerce plugin <= 2.11.31 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27539"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-28003",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yonifre",
      "product": "Maspik – Spam blacklist",
      "cwe": "CWE-79",
      "title": "WordPress Maspik – Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28003"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-28004",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-79",
      "title": "WordPress Business Directory plugin <= 6.4.25 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28004"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-28158",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lasso Analytics, Inc.",
      "product": "Do Lasso",
      "cwe": "CWE-79",
      "title": "WordPress Do Lasso plugin <= 358 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28158"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-28170",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1meril",
      "product": "Blog Floating Button",
      "cwe": "CWE-79",
      "title": "WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28170"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-28175",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-buy",
      "product": "Visitors Traffic Real Time Statistics",
      "cwe": "CWE-79",
      "title": "WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28175"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-28187",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "echoplugins",
      "product": "Knowledge Base for Documentation, FAQs with AI Assistance",
      "cwe": "CWE-79",
      "title": "WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 17.211.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28187"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-61960",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "WP Full Stripe Free",
      "cwe": "CWE-79",
      "title": "WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61960"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-61965",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ahmadgb",
      "product": "GeekyBot",
      "cwe": "CWE-79",
      "title": "WordPress GeekyBot plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61965"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-61974",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kitae Park",
      "product": "Mang Board WP",
      "cwe": "CWE-79",
      "title": "WordPress Mang Board WP plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61974"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-65580",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bracketweb",
      "product": "Agrion",
      "cwe": "CWE-79",
      "title": "WordPress Agrion theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65580"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-66426",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lester Chan",
      "product": "WP-Stats",
      "cwe": "CWE-79",
      "title": "WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66426"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-66429",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODEPRESS",
      "product": "Visitor Traffic Real Time Statistics Pro",
      "cwe": "CWE-79",
      "title": "WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66429"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-66449",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dylan Kuhn",
      "product": "Geo Mashup",
      "cwe": "CWE-79",
      "title": "WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66449"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-66468",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "powerfulwp",
      "product": "Local Delivery Drivers for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Local Delivery Drivers for WooCommerce plugin <= 3.0.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66468"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-66655",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multiparcels",
      "product": "MultiParcels Shipping For WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66655"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-66698",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "SureDash",
      "cwe": "CWE-79",
      "title": "WordPress SureDash plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66698"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-66700",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZAYTECH",
      "product": "Smart Online Order for Clover",
      "cwe": "CWE-79",
      "title": "WordPress Smart Online Order for Clover plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66700"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-65935",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "WiseConnect",
      "cwe": "CWE-305",
      "title": "Bypassing passkey entry in legacy pairing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65935"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-65932",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "BT122",
      "cwe": "CWE-440",
      "title": "BT122 stops advertising",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65932"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-65933",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "BT122",
      "cwe": "CWE-126",
      "title": "BT122 malformed packet with increased length field causes memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65933"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-65936",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "WiseConnect",
      "cwe": "CWE-126",
      "title": "RS9116W/SiWx917 malformed packet with increased length field causes memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65936"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-72506",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "National Institute of Information and Communications Technology",
      "product": "\"VoiceTra(Voice Translator)\" for Android",
      "cwe": "CWE-941",
      "title": "VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72506"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-53784",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Path Traversal via Symlink Module Root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53784"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-18511",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18511"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-18368",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teltonika Networks",
      "product": "RUTOS",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Modbusgwd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18368"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-19135",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The OpenNMS Group",
      "product": "Meridian",
      "cwe": "CWE-470",
      "title": "OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19135"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-73344",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Passionate Programmer Peter",
      "product": "WP Data Access",
      "cwe": "CWE-79",
      "title": "WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73344"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-58435",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-266",
      "title": "Gitea LFS Deploy-Key Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58435"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-73428",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "basecamp",
      "product": "trix",
      "cwe": "CWE-79",
      "title": "Trix: Stored XSS via HTMLParser attribute injection on paste",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73428"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-14332",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.0674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ecwid by Lightspeed Ecommerce Shopping Cart",
      "cwe": "CWE-862",
      "title": "Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14332"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-73571",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Collaboration",
      "cwe": "CWE-863",
      "title": "An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73571"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-56657",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Gitea SSH Key Parser Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56657"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-18509",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-285",
      "title": "IBM i is Affected By A Prvilege Escalation Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18509"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-0297",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "GlobalProtect App",
      "cwe": "CWE-787",
      "title": "GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0297"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-17069",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-352",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17069"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-14213",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-639",
      "title": "Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14213"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-27537",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Popup by Supsystic",
      "cwe": "CWE-79",
      "title": "WordPress Popup by Supsystic plugin <= 1.11.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27537"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-66687",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "WpBookingly",
      "cwe": "CWE-79",
      "title": "WordPress WpBookingly plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66687"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-73340",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fifu.app",
      "product": "Featured Image from URL",
      "cwe": "CWE-79",
      "title": "WordPress Featured Image from URL plugin <= 5.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73340"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-73357",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73357"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-73266",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-441",
      "title": "Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73266"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-12036",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Vantage",
      "cwe": "CWE-59",
      "title": "An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12036"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-73657",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-22",
      "title": "Trigger.dev: Cross-tenant payload poisoning via packet write + replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73657"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-0289",
      "cvss_base": 0.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00158,
      "epss_percentile": 0.05479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Browser",
      "cwe": "CWE-522",
      "title": "Prisma Browser: Inappropriate Implementation in Account Protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0289"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-15994",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Commercial Vantage",
      "cwe": "CWE-59",
      "title": "During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15994"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-73572",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Collaboration",
      "cwe": "CWE-79",
      "title": "In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73572"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-73628",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "s9y",
      "product": "Serendipity",
      "cwe": "CWE-79",
      "title": "Serendipity 2.3.5 Reflected XSS via search clean-URL route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73628"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-73037",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DayuanJiang",
      "product": "next-ai-draw-io",
      "cwe": "CWE-79",
      "title": "Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73037"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-73505",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JanDeDobbeleer",
      "product": "oh-my-posh",
      "cwe": "CWE-94",
      "title": "Oh My Posh: Arbitrary command execution via template injection in the path segment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73505"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-19182",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The OpenNMS Group",
      "product": "Meridian",
      "cwe": "CWE-863",
      "title": "OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19182"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-63423",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Accessories and Display Manager",
      "cwe": "CWE-321",
      "title": "During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63423"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-73481",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phplist",
      "product": "phplist3",
      "cwe": "CWE-352",
      "title": "phpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73481"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-18741",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Froiden",
      "product": "Worksuite SaaS",
      "cwe": "CWE-79",
      "title": "Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18741"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-0292",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00144,
      "epss_percentile": 0.0417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-290",
      "title": "Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0292"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2025-62315",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "AION",
      "cwe": "CWE-116",
      "title": "HCL AION is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62315"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-0290",
      "cvss_base": 0.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00141,
      "epss_percentile": 0.03963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Browser",
      "cwe": "CWE-522",
      "title": "Prisma Browser: Sensitive Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0290"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-67990",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.0375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-352",
      "title": "basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67990"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-53802",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-61",
      "title": "rsync < 3.5.0 Arbitrary File Read via Symlink Following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53802"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-53785",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Path Traversal Write Escape via --relative Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53785"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-19293",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "WiseConnect",
      "cwe": "CWE-521",
      "title": "SMP security request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19293"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-53803",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Symlink Following Arbitrary File Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53803"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-6387",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "System Update",
      "cwe": "CWE-290",
      "title": "A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6387"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-72658",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery in Kibana Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72658"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-68451",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Validate length for CCA ECC private key requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68451"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-63426",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Dock Manager",
      "cwe": "CWE-59",
      "title": "During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63426"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-56755",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-284",
      "title": "Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56755"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-68454",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: pci: Fix handling of AIF enable without AISB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68454"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-68452",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Validate length for CCA AES cipher key requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68452"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-73506",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JanDeDobbeleer",
      "product": "oh-my-posh",
      "cwe": "CWE-150",
      "title": "Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73506"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-68453",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Fix buffer over-read in cca_cipher2protkey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68453"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-72849",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-352",
      "title": "Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72849"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-17029",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17029"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-18622",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-451",
      "title": "Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18622"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-0294",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-427",
      "title": "Prisma Access Agent: Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0294"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-0291",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.0219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-59",
      "title": "Prisma Access Agent: Authenticated Limited File Deletion on Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0291"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-11970",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.0209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forcepoint",
      "product": "F1E mac",
      "cwe": "CWE-754",
      "title": "This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11970"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-73480",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dundee",
      "product": "gdu",
      "cwe": "CWE-116",
      "title": "gdu Terminal Injection via Unstripped Escape Sequences",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73480"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-73479",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Byron",
      "product": "dua-cli",
      "cwe": "CWE-116",
      "title": "dua-cli Terminal Escape Sequence Injection via Marked Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73479"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-58441",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "Gitea Open Source Git Server",
      "cwe": "CWE-918",
      "title": "SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58441"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-14875",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Client Solutions",
      "cwe": "CWE-426",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14875"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-14663",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-313",
      "title": "PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14663"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-0293",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-693",
      "title": "Prisma Access Agent: Anti-Tamper Protection Bypass on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0293"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-16898",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-73",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16898"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-16987",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-73",
      "title": "IBM i is Affected By An Improper Validation Vulnerability in PASE []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16987"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-13365",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Planning Analytics",
      "cwe": "CWE-352",
      "title": "IBM Planning Analytics Local is affected by security vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13365"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-73575",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zimbra",
      "product": "Collaboration",
      "cwe": "CWE-352",
      "title": "In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73575"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-63425",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Dock Manager",
      "cwe": "CWE-276",
      "title": "During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63425"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-19483",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Storage Scale",
      "cwe": "CWE-532",
      "title": "The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19483"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-56865",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go toolchain",
      "product": "cmd/go",
      "cwe": "CWE-347",
      "title": "Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56865"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-19696",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19696"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-19730",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-459",
      "title": "Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19730"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-65934",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "BT122",
      "cwe": "CWE-440",
      "title": "BT122 plaintext pause encryption request causes DOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65934"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-73585",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-377",
      "title": "Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73585"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2025-62314",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "AION",
      "cwe": "CWE-307",
      "title": "HCL AION is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62314"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-12236",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-835",
      "title": "Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12236"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-18101",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18101"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-19088",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.0093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ShopEngine Elementor WooCommerce Builder Addon",
      "cwe": "CWE-352",
      "title": "ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19088"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-19694",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19694"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-19695",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19695"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-63424",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Dock Manager",
      "cwe": "CWE-261",
      "title": "During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63424"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-73583",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73583"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-53796",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53796"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-18071",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By An Improper Management Vulnerability in HTTP Server []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18071"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-0296",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "GlobalProtect App",
      "cwe": "CWE-295",
      "title": "GlobalProtect App: Improper Certificate Validation Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0296"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-53797",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Symlink Race Condition Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53797"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-53800",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Symlink Race Condition via --remove-source-files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53800"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-53799",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RsyncProject",
      "product": "rsync",
      "cwe": "CWE-59",
      "title": "rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53799"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-73584",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.0057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-377",
      "title": "Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73584"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-17438",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-269",
      "title": "IBM i is Affected By An Improper Privilege Management Vulnerability in LDAP []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17438"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-14256",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "E16 Gen 2 (Type 21M5, 21M6) Laptops (ThinkPad) ELAN TrackPoint Device Driver for Windows 11 (Version 23H2 or later) - ThinkPad",
      "cwe": "CWE-125",
      "title": "ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14256"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-18086",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18086"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2025-52640",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00086,
      "epss_percentile": 0.00399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "AION",
      "cwe": "CWE-276",
      "title": "HCL AION is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52640"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2025-62318",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00085,
      "epss_percentile": 0.00349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "AION",
      "cwe": "CWE-352",
      "title": "HCL AION is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62318"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-0295",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "GlobalProtect App",
      "cwe": "CWE-362",
      "title": "GlobalProtect App: Local Privilege Escalation via Race Condition on macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0295"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-14681",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.00219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PostgreSQL",
      "cwe": "CWE-924",
      "title": "PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14681"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-16896",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00073,
      "epss_percentile": 0.00071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-367",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16896"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-16458",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0007,
      "epss_percentile": 0.00044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oberon microsystems AG",
      "product": "ocrypto",
      "cwe": "CWE-208",
      "title": "Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16458"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-16459",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0007,
      "epss_percentile": 0.00045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oberon microsystems AG",
      "product": "Oberon PSA Crypto",
      "cwe": "CWE-208",
      "title": "Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16459"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2015-1701",
      "detail": "EXPLOIT PUBLISHED — CVE-2015-1701. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2016-20097",
      "detail": "EXPLOIT PUBLISHED — CVE-2016-20097 (Weaver Network Co., Ltd. E-cology 8.0). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-0144",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-0144 (Microsoft Corporation Windows SMB). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-0145",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-0145 (Microsoft Corporation Windows SMB). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-11357",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-11357. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-18362",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-18362. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-19320",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-19320. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-19321",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-19321. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-19322",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-19322. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-19323",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-19323. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-20753",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-20753. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-6882",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-6882. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-8453",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-8453 (Microsoft Windows 7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-1055",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-1055 (Linux Kernel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-2586",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-2586 (Linux Kernel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-4995",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-4995 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-50997",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-50997 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-7028",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-7028 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-15684",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-15684 (Open5GS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-9486",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-9486 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13177",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13177 (Unknown Eventin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13612",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13612 (Unknown KiviCare). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14857",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14857 (Unknown WP Crowdfunding). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15216 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15217",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15217 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15423",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15423 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16494 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16627",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16627 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18433",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18433 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19246",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19246 (HKUDS nanobot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19345",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19345 (code-projects Task Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3087",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3087 (Python Software Foundation CPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39931",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39931 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39932",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39932 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41453",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41453 (krayin laravel-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42578 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42579 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42584 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4879",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4879 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50559",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50559 (quarkusio quarkus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50656",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50656 (Microsoft Malware Protection Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61523 (WebsiteBaker Org e.V. WebsiteBaker CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61524",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61524 (WebsiteBaker Org e.V. WebsiteBaker CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63720",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63720 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66748",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66748 (owen2345 camaleon-cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66752",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66752 (tiny-http). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66753",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66753 (tiny-http). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67610",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67610 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67611",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67611 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67612",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67612 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67617",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67617 (microweber). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67620 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67621",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67621 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67622",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67622 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6821",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6821 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69100",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69100 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70636",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70636 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70637",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70637 (hfiref0x LightFTP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71959",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71959 (bitwarden server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71962",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71962 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71964",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71964 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71965",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71965 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71966",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71966 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71969",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71969 (OP-TEE optee_os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73678",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7427",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7427 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-8667",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-8667 (GitLab). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2018-19943",
      "detail": "RESCORED — CVE-2018-19943 (QNAP Systems Inc. QTS). CVSS 8 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-48979",
      "detail": "RESCORED — CVE-2022-48979 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-49159",
      "detail": "RESCORED — CVE-2022-49159 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12539",
      "detail": "RESCORED — CVE-2026-12539 (Docker Sandboxes). CVSS 5.1 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42579",
      "detail": "RESCORED — CVE-2026-42579 (netty). CVSS 7.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42581",
      "detail": "RESCORED — CVE-2026-42581 (netty). CVSS 5.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42584",
      "detail": "RESCORED — CVE-2026-42584 (netty). CVSS 7.3 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-45674",
      "detail": "RESCORED — CVE-2026-45674 (netty). CVSS 8.7 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47691",
      "detail": "RESCORED — CVE-2026-47691 (netty). CVSS 8.7 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48043",
      "detail": "RESCORED — CVE-2026-48043 (netty). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54230",
      "detail": "RESCORED — CVE-2026-54230 (Red Hat Enterprise Linux 8). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-2586",
      "detail": "ENRICHED — CVE-2022-2586 (Linux Kernel). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-48633",
      "detail": "ENRICHED — CVE-2022-48633 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-48823",
      "detail": "ENRICHED — CVE-2022-48823 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-48825",
      "detail": "ENRICHED — CVE-2022-48825 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49044",
      "detail": "ENRICHED — CVE-2022-49044 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49051",
      "detail": "ENRICHED — CVE-2022-49051 (Linux). Received CVSS 6.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49069",
      "detail": "ENRICHED — CVE-2022-49069 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49109",
      "detail": "ENRICHED — CVE-2022-49109 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49112",
      "detail": "ENRICHED — CVE-2022-49112 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49118",
      "detail": "ENRICHED — CVE-2022-49118 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49132",
      "detail": "ENRICHED — CVE-2022-49132 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49133",
      "detail": "ENRICHED — CVE-2022-49133 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49169",
      "detail": "ENRICHED — CVE-2022-49169 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49286",
      "detail": "ENRICHED — CVE-2022-49286 (Linux). Received CVSS 4.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49309",
      "detail": "ENRICHED — CVE-2022-49309 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
