{
  "day": "2026-08-14",
  "boundary": "UTC calendar day",
  "published_count": 201,
  "by_severity": {
    "CRITICAL": 25,
    "HIGH": 80,
    "MEDIUM": 75,
    "LOW": 20
  },
  "kev_count": 0,
  "exploit_reference_count": 2,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-19771",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02795,
      "epss_percentile": 0.85295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Baicells",
      "product": "EG3661M",
      "cwe": "CWE-77",
      "title": "Baicells EG3661M LuCI Web luci os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19771"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-19681",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02238,
      "epss_percentile": 0.81411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19681"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-19628",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.02005,
      "epss_percentile": 0.79235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19628"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-19682",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01928,
      "epss_percentile": 0.78338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19682"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-19188",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0189,
      "epss_percentile": 0.77899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Haiwell",
      "product": "Haiwell IoT Cloud HMI Gateway",
      "cwe": "CWE-78",
      "title": "Haiwell IoT Cloud HMI Gateway OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19188"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-19679",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01563,
      "epss_percentile": 0.73283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Improper Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19679"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-73680",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01476,
      "epss_percentile": 0.71774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cockpit HQ",
      "product": "Cockpit CMS",
      "cwe": "CWE-78",
      "title": "Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73680"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-17179",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01008,
      "epss_percentile": 0.60306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-78",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17179"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-16915",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00854,
      "epss_percentile": 0.55463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-22",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16915"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-18554",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00854,
      "epss_percentile": 0.55463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-22",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18554"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-73678",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00816,
      "epss_percentile": 0.54272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MindsDB",
      "product": "Minds Platform",
      "cwe": "CWE-94",
      "title": "MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73678"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-17184",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00795,
      "epss_percentile": 0.5358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-73",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17184"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-19626",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0079,
      "epss_percentile": 0.53433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-95",
      "title": "Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19626"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-17182",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00767,
      "epss_percentile": 0.52686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-287",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17182"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-17173",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0064,
      "epss_percentile": 0.47929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-22",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17173"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-73679",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0061,
      "epss_percentile": 0.46526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImpressCMS",
      "product": "ImpressCMS",
      "cwe": "CWE-94",
      "title": "ImpressCMS Authenticated RCE via PHP Custom Tag eval()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73679"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-17175",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.46119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-287",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17175"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-19813",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.46149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19813"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-19822",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.4615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E QoS Edit editQos lstAdd stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19822"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-19847",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.46149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19847"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-17181",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00593,
      "epss_percentile": 0.45766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-22",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17181"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-17081",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00593,
      "epss_percentile": 0.45766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-22",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17081"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2025-7639",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00571,
      "epss_percentile": 0.44703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVEVA",
      "product": "AVEVA Enterprise SCADA",
      "cwe": "CWE-502",
      "title": "AVEVA Enterprise SCADA Deserialization of Untrusted Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7639"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-17177",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00549,
      "epss_percentile": 0.43572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-674",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17177"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-73673",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00545,
      "epss_percentile": 0.43375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netis Systems Co., Ltd.",
      "product": "Netis NC63 Wireless AC1200 Router",
      "cwe": "CWE-306",
      "title": "Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73673"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-16879",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00528,
      "epss_percentile": 0.4248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-285",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16879"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-66271",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00521,
      "epss_percentile": 0.42078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-434",
      "title": "Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66271"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-50027",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00503,
      "epss_percentile": 0.40924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "doobidoo",
      "product": "mcp-memory-service",
      "cwe": "CWE-306",
      "title": "mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50027"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-72819",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72819"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-72970",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-122",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72970"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-73633",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00498,
      "epss_percentile": 0.40666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Struts",
      "cwe": "CWE-400",
      "title": "Apache Struts: Unbounded read of a JSON request body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73633"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-19812",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19812"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-19844",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19844"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-73849",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00484,
      "epss_percentile": 0.39788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-306",
      "title": "emlog allows unauthenticated reinstallation via `install.php?action=reinstall`.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73849"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-19827",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00479,
      "epss_percentile": 0.39483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alldatacenter",
      "product": "alldata",
      "cwe": "CWE-22",
      "title": "alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19827"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-19830",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00474,
      "epss_percentile": 0.39192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-816DRM",
      "cwe": "CWE-400",
      "title": "TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19830"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-72827",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-1336",
      "title": "Grav CMS before 2.0.13 Remote Code Execution via Twig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72827"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-16905",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00469,
      "epss_percentile": 0.38781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-287",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16905"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-17186",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00468,
      "epss_percentile": 0.38758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-78",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17186"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-72824",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00467,
      "epss_percentile": 0.38704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav before 1.0.13 API Key Scope Bypass via PagesController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72824"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-19788",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC1206",
      "cwe": "CWE-119",
      "title": "Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19788"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-19789",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC1206",
      "cwe": "CWE-119",
      "title": "Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19789"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-19790",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "G0",
      "cwe": "CWE-119",
      "title": "Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19790"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-19791",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "G0",
      "cwe": "CWE-119",
      "title": "Tenda G0 httpd web management interface module addStaticRoute stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19791"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-19792",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "G0",
      "cwe": "CWE-119",
      "title": "Tenda G0 httpd web management interface module setPortMapping buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19792"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-19811",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19811"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-19814",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19814"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-19815",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19815"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-19821",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC12",
      "cwe": "CWE-119",
      "title": "Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19821"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-19823",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19823"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-19824",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19824"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-19845",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19845"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-19846",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.3865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A800R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19846"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-18178",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00443,
      "epss_percentile": 0.37071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-22",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18178"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-73683",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel",
      "product": "Socialite",
      "cwe": "CWE-294",
      "title": "Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73683"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-72830",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0044,
      "epss_percentile": 0.36835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-269",
      "title": "Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72830"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-34492",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Airwall",
      "cwe": "CWE-73",
      "title": "Airwall - Arbitrary file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34492"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-17209",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00426,
      "epss_percentile": 0.3571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-79",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17209"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-19762",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00424,
      "epss_percentile": 0.35607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DTStack",
      "product": "Taier",
      "cwe": "CWE-22",
      "title": "DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19762"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-66270",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-434",
      "title": "Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66270"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-46603",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/image",
      "product": "golang.org/x/image/vp8l",
      "cwe": "CWE-789",
      "title": "Excessive memory allocation during VP8L decoding in golang.org/x/image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46603"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-19825",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Client Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Client Management System Master.php save_service sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19825"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-16708",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-15",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16708"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-58224",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.3387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-353",
      "title": "Samba: ctdb fails to do integrity checking of received packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58224"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-48528",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.3379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NCEAS",
      "product": "metacat",
      "cwe": "CWE-89",
      "title": "Metacat has an unauthenticated SQL injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48528"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-72815",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-chi",
      "product": "chi",
      "cwe": "CWE-290",
      "title": "go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72815"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-72813",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.3279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actix",
      "product": "actix-web",
      "cwe": "CWE-248",
      "title": "actix-files before 0.6.10 Denial of Service via empty Range header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72813"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-19631",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00392,
      "epss_percentile": 0.32468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-89",
      "title": "SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19631"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-19871",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-798",
      "title": "Use of hard-coded credentials in Prospero Flow CRM employee onboarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19871"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-72814",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actix",
      "product": "actix-web",
      "cwe": "CWE-22",
      "title": "actix-web before 0.6.10 Information Disclosure via Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72814"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-19763",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DTStack",
      "product": "Taier",
      "cwe": "CWE-22",
      "title": "DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19763"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-19837",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00373,
      "epss_percentile": 0.30563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-200",
      "title": "Webkul Bagisto Customer Search search information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19837"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-19629",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-863",
      "title": "Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19629"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-17079",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00367,
      "epss_percentile": 0.29893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-693",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17079"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-19829",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00365,
      "epss_percentile": 0.2976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "648540858",
      "product": "wvp-GB28181-pro",
      "cwe": "CWE-22",
      "title": "648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19829"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-63650",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00364,
      "epss_percentile": 0.29635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-295",
      "title": "OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63650"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-72822",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-306",
      "title": "Grav before 1.0.13 Authentication Bypass via disable2fa",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72822"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-69101",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datavane",
      "product": "tis",
      "cwe": "CWE-611",
      "title": "Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69101"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-12949",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.27013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wishlist Member",
      "product": "Wishlist Member",
      "cwe": "CWE-640",
      "title": "Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12949"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-72820",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.26977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-22",
      "title": "Grav 2.0.11 Path Traversal via Backup Profile Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72820"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-72835",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-41",
      "title": "filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72835"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-45699",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "netatalk",
      "cwe": "CWE-191",
      "title": "Netatalk has Integer Underflow → Stack Buffer Overflow in copydir()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45699"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-73051",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actix",
      "product": "actix-web",
      "cwe": "CWE-444",
      "title": "actix-http before 3.12.1 HTTP Request Smuggling via CL.TE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73051"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-19909",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PAX Technology",
      "product": "Q80",
      "cwe": "CWE-59",
      "title": "PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19909"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-17227",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-89",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17227"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-19880",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QOS.CH Sarl",
      "product": "Logback-classic",
      "cwe": "CWE-22",
      "title": "Incomplete protection against CVE-2025-11226",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19880"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-63649",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-183",
      "title": "The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63649"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-19826",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alldatacenter",
      "product": "alldata",
      "cwe": "CWE-20",
      "title": "alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19826"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-15205",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paymob for WooCommerce",
      "cwe": "CWE-89",
      "title": "Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15205"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-72836",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-178",
      "title": "FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72836"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-72810",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72810"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-19680",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-89",
      "title": "SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19680"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-19834",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00309,
      "epss_percentile": 0.23577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-285",
      "title": "Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19834"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2025-71405",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-chi",
      "product": "chi",
      "cwe": "CWE-601",
      "title": "go-chi chi before v5.2.2 Open Redirect via RedirectSlashes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71405"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-74245",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-306",
      "title": "Quay: unauthenticated exported logs download in quay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74245"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-63361",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.2316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63361"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-72826",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-266",
      "title": "Grav before 1.0.13 Scope Bypass via createApiKey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72826"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-72829",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-269",
      "title": "Grav before 1.0.13 API Key Scope Bypass via UsersController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72829"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-72831",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-863",
      "title": "Grav through 2.0.11 Authentication Bypass via Flex Objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72831"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-72837",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-284",
      "title": "File Browser before 2.63.20 Privilege Escalation via Proxy Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72837"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-49826",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00299,
      "epss_percentile": 0.22519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "concourse",
      "product": "concourse",
      "cwe": "CWE-601",
      "title": "Concourse login flow has an open redirect issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49826"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-72838",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.2212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-770",
      "title": "FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72838"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-19639",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-1284",
      "title": "Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19639"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-19836",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00294,
      "epss_percentile": 0.21985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-285",
      "title": "Webkul Bagisto Backend Customer Detail Feature view authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19836"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-19838",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00294,
      "epss_percentile": 0.21985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-285",
      "title": "Webkul Bagisto Backend Reporting Endpoint sales authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19838"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-14290",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Embed Google Photos album",
      "cwe": "CWE-79",
      "title": "Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14290"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-19828",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00288,
      "epss_percentile": 0.21404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "648540858",
      "product": "wvp-GB28181-pro",
      "cwe": "CWE-22",
      "title": "648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19828"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-1621",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Universal Software Inc.",
      "product": "E-Municipality",
      "cwe": "CWE-305",
      "title": "Register Bypass in Universal Sotware's E-Municipality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1621"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-19870",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19870"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-18403",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-89",
      "title": "LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18403"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-18039",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Essential Addons for Elementor",
      "cwe": "CWE-269",
      "title": "Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18039"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-19768",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-94",
      "title": "Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19768"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-72812",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Missing Authorization via refreshBacklink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72812"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-72828",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-269",
      "title": "Grav before 1.0.13 API Key Scope Bypass via InvitationsController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72828"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-73850",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-89",
      "title": "Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73850"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-49989",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crate",
      "product": "crate",
      "cwe": "CWE-863",
      "title": "CrateDB's Blob HTTP handler bypasses authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49989"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-27871",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00269,
      "epss_percentile": 0.19202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "TL280",
      "cwe": "CWE-327",
      "title": "TL280",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27871"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-19784",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00268,
      "epss_percentile": 0.19014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "francoisjacquet",
      "product": "RosarioSIS",
      "cwe": "CWE-285",
      "title": "francoisjacquet RosarioSIS Referrals.php DBUpdate authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19784"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-16810",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitpressadmin",
      "product": "Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder",
      "cwe": "CWE-89",
      "title": "Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16810"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-12743",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cservit",
      "product": "affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display",
      "cwe": "CWE-89",
      "title": "affiliate-toolkit <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12743"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-18109",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldgrid",
      "product": "W3 Total Cache",
      "cwe": "CWE-79",
      "title": "W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18109"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-19835",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-266",
      "title": "Webkul Bagisto Customer Item Deletion Endpoint access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19835"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-72833",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-269",
      "title": "Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72833"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-19636",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-1270",
      "title": "Insuffucient Protections Lead to Brute Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19636"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-74242",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-639",
      "title": "Quay: repository notification uuid idor in quay api",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74242"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-74243",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-306",
      "title": "Quay: unauthenticated secscan notification endpoint in quay when psk is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74243"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-74250",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-226",
      "title": "In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74250"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-19764",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Raisecom",
      "product": "Communication Command and Dispatch Management Platform",
      "cwe": "CWE-74",
      "title": "Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19764"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-66272",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-200",
      "title": "Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66272"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-72811",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0025,
      "epss_percentile": 0.16727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan before v3.7.4 SQL Injection via backlink search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72811"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-19767",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewdoctortimings.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19767"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-53472",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16428,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "migration-planner",
      "cwe": "CWE-79",
      "title": "Migration-planner: credentialurl validator accepts javascript: urls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53472"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-71570",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icagenda.com",
      "product": "iCagenda extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71570"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-19879",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-681",
      "title": "Io.undertow/undertow: undertow: http response header integrity issue due to character truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19879"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-50029",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sunnyadn",
      "product": "js-toml",
      "cwe": "CWE-697",
      "title": "js-toml has silent type confusion via falsy-primitive duplicate-key bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50029"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-67365",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00228,
      "epss_percentile": 0.13789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icagenda.com",
      "product": "iCagenda extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67365"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-72834",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-200",
      "title": "filebrowser before 2.63.19 Permission Bypass via checksum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72834"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-69414",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.1369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Malware Protection Engine",
      "cwe": "CWE-284",
      "title": "Microsoft Defender Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69414"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-19839",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Doctors Appointment System",
      "cwe": "CWE-284",
      "title": "SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19839"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-19908",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.1339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PAX Technology",
      "product": "Q80",
      "cwe": "CWE-306",
      "title": "PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19908"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-73845",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ondata",
      "product": "ckan-mcp-server",
      "cwe": "CWE-20",
      "title": "CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73845"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-57469",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KUNBUS",
      "product": "PiCtory",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57469"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-73844",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.13157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ondata",
      "product": "ckan-mcp-server",
      "cwe": "CWE-209",
      "title": "CKAN MCP Server: Information disclosure via verbose error reflection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73844"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-16739",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Epeken All Kurir for Woocommerce",
      "cwe": "CWE-287",
      "title": "Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16739"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-72816",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-chi",
      "product": "chi",
      "cwe": "CWE-290",
      "title": "go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72816"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-71571",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icagenda.com",
      "product": "iCagenda extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71571"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-50523",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "PowerShell 7.4",
      "cwe": "CWE-77",
      "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50523"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-19787",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.11502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Air Cargo Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19787"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-19765",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eyaushev",
      "product": "swagger-testcase-mcp",
      "cwe": "CWE-918",
      "title": "eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19765"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-73630",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-203",
      "title": "SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73630"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-19785",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "francoisjacquet",
      "product": "RosarioSIS",
      "cwe": "CWE-74",
      "title": "francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19785"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-16772",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akaunting",
      "product": "Akaunting",
      "cwe": "CWE-269",
      "title": "CVE-2026-16772",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16772"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-72825",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav before 1.0.13 API-key scope cap bypass via ReportsController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72825"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-73048",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73048"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-73049",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-863",
      "title": "SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73049"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-72823",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav before 1.0.13 API-key scope cap bypass via DemoController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72823"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-19635",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Security Center",
      "cwe": "CWE-78",
      "title": "Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19635"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-19794",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gamerz",
      "product": "WP-Stats",
      "cwe": "CWE-79",
      "title": "WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19794"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-74240",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-287",
      "title": "Quay: jwt claim validation bypasses in quay federated robot and sso authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74240"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-74248",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.0896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Octavia",
      "cwe": "CWE-863",
      "title": "OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74248"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-19910",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PAX Technology",
      "product": "Q80",
      "cwe": "CWE-347",
      "title": "PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19910"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-19841",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDNET",
      "product": "TEW-813DRU",
      "cwe": "CWE-266",
      "title": "TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19841"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-74241",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-90",
      "title": "Quay: ldap referral filter injection in quay external ldap authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74241"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-72859",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-863",
      "title": "Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72859"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-72832",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav before 2.0.12 Stored XSS via quoted-attribute bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72832"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-46439",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oscal-compass",
      "product": "compliance-trestle",
      "cwe": "CWE-94",
      "title": "compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46439"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-53970",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lucasgelfond",
      "product": "ZeroBrew",
      "cwe": "CWE-494",
      "title": "ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53970"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-12363",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12363"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-73847",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-352",
      "title": "Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73847"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-19786",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "francoisjacquet",
      "product": "RosarioSIS",
      "cwe": "CWE-352",
      "title": "francoisjacquet RosarioSIS Modules.php cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19786"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-47192",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00165,
      "epss_percentile": 0.06166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siemens",
      "product": "kas",
      "cwe": "CWE-347",
      "title": "kas's late signature validation may allow unnoticed repository manipulations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47192"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-47766",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containers",
      "product": "crun",
      "cwe": "CWE-61",
      "title": "crun follows rootfs /dev symlink while creating default devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47766"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-47191",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siemens",
      "product": "kas",
      "cwe": "CWE-347",
      "title": "kas checks out SHA-like git branches as valid commits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47191"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-64887",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Airwall",
      "cwe": "CWE-321",
      "title": "Airwall - Hardcoded Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64887"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-67366",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icagenda.com",
      "product": "iCagenda extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67366"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2025-10308",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alian",
      "product": "Astro Booking Engine",
      "cwe": "CWE-352",
      "title": "Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10308"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-72817",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.0475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-chi",
      "product": "chi",
      "cwe": "CWE-345",
      "title": "go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72817"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-49457",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00149,
      "epss_percentile": 0.04635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "erlang_quic",
      "cwe": "CWE-295",
      "title": "QUIC has Broken TLS verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49457"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-74244",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-347",
      "title": "Quay: stripe webhook accepts forged events without signature verification in quay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74244"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-72821",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72821"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-73846",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ondata",
      "product": "ckan-mcp-server",
      "cwe": "CWE-345",
      "title": "CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73846"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-49282",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "capstone-engine",
      "product": "capstone",
      "cwe": "CWE-125",
      "title": "Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and process crashes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49282"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-74247",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-918",
      "title": "Quay: ssrf via build archive_url in quay build api",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74247"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-19884",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-15",
      "title": "In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own `@theia/git` extension and the builtin VS Code `git` extension run git commands such as `git status` as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled `.git/config` with `core.fsmonitor` (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt. As of 1.70.0, plugins that declare `capabilities.untrustedWorkspaces.supported: false`, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated `@theia/git` extension has been removed, so no git command is executed against an untrusted folder.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19884"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-49263",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00128,
      "epss_percentile": 0.0292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "capstone-engine",
      "product": "capstone",
      "cwe": "CWE-197",
      "title": "Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and parser desynchronization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49263"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-57472",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KUNBUS",
      "product": "RevPiPyLoad",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57472"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-57471",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KUNBUS",
      "product": "RevPiPyLoad",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57471"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-12366",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12366"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-12364",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.0209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-822",
      "title": "Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12364"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-49986",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cdeust",
      "product": "Cortex",
      "cwe": "CWE-829",
      "title": "Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49986"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-19617",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19617"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-19770",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0011,
      "epss_percentile": 0.01467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feedmob",
      "product": "fm-mcp-servers",
      "cwe": "CWE-918",
      "title": "feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19770"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-13002",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.0135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13002"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-46380",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oscal-compass",
      "product": "compliance-trestle",
      "cwe": "CWE-918",
      "title": "compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46380"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-12365",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12365"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-13196",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KUNBUS",
      "product": "piControl",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in KUNBUS piControl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13196"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-13197",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00096,
      "epss_percentile": 0.00807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KUNBUS",
      "product": "piControl",
      "cwe": "CWE-362",
      "title": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13197"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-13198",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KUNBUS",
      "product": "piControl",
      "cwe": "CWE-362",
      "title": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13198"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-63700",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00086,
      "epss_percentile": 0.00391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-269",
      "title": "Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63700"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-63701",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-269",
      "title": "Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63701"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-63702",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00079,
      "epss_percentile": 0.00177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-798",
      "title": "Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63702"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2010-0738",
      "detail": "EXPLOIT PUBLISHED — CVE-2010-0738. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2010-1428",
      "detail": "EXPLOIT PUBLISHED — CVE-2010-1428. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2010-2861",
      "detail": "EXPLOIT PUBLISHED — CVE-2010-2861. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2012-0507",
      "detail": "EXPLOIT PUBLISHED — CVE-2012-0507. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2016-3351",
      "detail": "EXPLOIT PUBLISHED — CVE-2016-3351. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25765",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25765 (ASP-CMS Project ASP-CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-30116",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-30116. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-30119",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-30119. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13328",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13328 (Unknown Food Menu). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13610",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13610 (Unknown KiviCare). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14229",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14229 (Unknown ECS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14230",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14230 (Unknown ECS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16541",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16611",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18216 (Unknown Backup Migration). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18807",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18807 (Unknown ECS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19710 (SourceCodester Simple Student Information System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19750",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19750 (Tenda CH). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19752",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19752 (EnzoVezzaro mcp-dominican-layer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19753",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19753 (Model Context Protocol mcp-rdf-explorer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19895",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19897",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19897 (mangroup dtale). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19900",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19903",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19917",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19920",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19920 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34881 (OpenStack Glance). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39883",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39883 (open-telemetry opentelemetry-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4035",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4035 (mlflow/mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43001",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43001 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54297 (lostisland faraday). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59109",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59109 (Zalktis Programmas (SIA \"Zalktis Programmas\") Zalktis). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62241 (MohibShaikh clawvet). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72741",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72741 (goodrain rainbond). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72777",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72777 (DayuanJiang next-ai-draw-io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73037",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73037 (DayuanJiang next-ai-draw-io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73481",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73481 (phplist3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73482",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73482 (phplist3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73506",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73506 (JanDeDobbeleer oh-my-posh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73514",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73514 (PostGIS address_standardizer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73515",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73515 (PostGIS). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2016-1019",
      "detail": "RESCORED — CVE-2016-1019. CVSS 7.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-30116",
      "detail": "RESCORED — CVE-2021-30116. CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-30120",
      "detail": "RESCORED — CVE-2021-30120. CVSS 9.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-13601",
      "detail": "RESCORED — CVE-2026-13601 (Red Hat Enterprise Linux 8). CVSS 7.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19757",
      "detail": "RESCORED — CVE-2026-19757 (Dromara lamp-cloud). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19758",
      "detail": "RESCORED — CVE-2026-19758 (dromara lamp-cloud). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-20156",
      "detail": "RESCORED — CVE-2026-20156 (Cisco RoomOS Software). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-20157",
      "detail": "RESCORED — CVE-2026-20157 (Cisco RoomOS Software). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34993",
      "detail": "RESCORED — CVE-2026-34993 (aio-libs aiohttp). CVSS 6.4 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4035",
      "detail": "RESCORED — CVE-2026-4035 (mlflow/mlflow). CVSS 9.1 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-43001",
      "detail": "RESCORED — CVE-2026-43001 (OpenStack Keystone). CVSS 7.9 → 8 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
