{
  "day": "2026-08-17",
  "boundary": "UTC calendar day",
  "published_count": 338,
  "by_severity": {
    "CRITICAL": 66,
    "HIGH": 111,
    "MEDIUM": 121,
    "LOW": 38
  },
  "kev_count": 0,
  "exploit_reference_count": 20,
  "awaiting_enrichment_count": 2,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-73522",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.02361,
      "epss_percentile": 0.82419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "COVESA",
      "product": "Open1722",
      "cwe": "CWE-121",
      "title": "COVESA Open1722 0.9.2 Stack Buffer Overflow via avtp_to_can() in acf-can-listener",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73522"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-19976",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.02055,
      "epss_percentile": 0.79741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "COMFAST",
      "product": "CF-N1-S",
      "cwe": "CWE-77",
      "title": "COMFAST CF-N1-S mbox-config sub_44A968 command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19976"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-73851",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01479,
      "epss_percentile": 0.71825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-22",
      "title": "Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73851"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-75002",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.01324,
      "epss_percentile": 0.68664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-77",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75002"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-50776",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01323,
      "epss_percentile": 0.68615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50776"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-19983",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01308,
      "epss_percentile": 0.68318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "A1300",
      "cwe": "CWE-78",
      "title": "GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19983"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-64849",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01109,
      "epss_percentile": 0.6328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow",
      "cwe": "CWE-918",
      "title": "MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64849"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-75011",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01088,
      "epss_percentile": 0.62669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kylecui",
      "product": "NetForensicMCP",
      "cwe": "CWE-77",
      "title": "kylecui NetForensicMCP index.js execAsync command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75011"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-19981",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0105,
      "epss_percentile": 0.61586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "A1300",
      "cwe": "CWE-78",
      "title": "GL.iNet XE3000 Wi-Fi Timer Power-Schedule Feature os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19981"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-19982",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0105,
      "epss_percentile": 0.61586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "BE9300",
      "cwe": "CWE-77",
      "title": "GL.iNet BE9300/MT6000 Firewall-management RPC os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19982"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-74843",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00967,
      "epss_percentile": 0.59053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WN531P3",
      "cwe": "CWE-121",
      "title": "Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74843"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-67918",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00908,
      "epss_percentile": 0.57146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67918"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-75047",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0086,
      "epss_percentile": 0.55673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-409",
      "title": "In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75047"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2025-27770",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00825,
      "epss_percentile": 0.54557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uptrain-ai",
      "product": "uptrain",
      "cwe": "CWE-74",
      "title": "UpTrain vulnerable to Remote code execution at `/create_project`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27770"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2025-27771",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00825,
      "epss_percentile": 0.54557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uptrain-ai",
      "product": "uptrain",
      "cwe": "CWE-74",
      "title": "Uptrain vulnerable to remote code execution via `/add_prompts` endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27771"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2025-27772",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00825,
      "epss_percentile": 0.54557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uptrain-ai",
      "product": "uptrain",
      "cwe": "CWE-74",
      "title": "Uptrain vulnerable to remote code execution via `/new_run` endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27772"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-65640",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00814,
      "epss_percentile": 0.54192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress",
      "product": "WordPress",
      "cwe": "CWE-434",
      "title": "WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65640"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-75050",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00797,
      "epss_percentile": 0.53655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-770",
      "title": "In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75050"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-74997",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00766,
      "epss_percentile": 0.52652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-78",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74997"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-19478",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00719,
      "epss_percentile": 0.51025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code ('Code Injection') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19478"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-68004",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00717,
      "epss_percentile": 0.50953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68004"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-19977",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00711,
      "epss_percentile": 0.50742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EFM",
      "product": "ipTIME A3004T",
      "cwe": "CWE-287",
      "title": "EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19977"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-67919",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.007,
      "epss_percentile": 0.50359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67919"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-19978",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00692,
      "epss_percentile": 0.50059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jiantao88",
      "product": "android-mcp-server",
      "cwe": "CWE-78",
      "title": "jiantao88 android-mcp-server Command Execution index.js child_process.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19978"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-59902",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00684,
      "epss_percentile": 0.49763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty: Memory Exhaustion in SctpMessageCompletionHandler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59902"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-16139",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00653,
      "epss_percentile": 0.48505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "ShareFile Storage Zones Controller",
      "cwe": "CWE-20",
      "title": "Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16139"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-74845",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0065,
      "epss_percentile": 0.48381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "2100 Technology",
      "product": "Official Document Management System",
      "cwe": "CWE-434",
      "title": "2100 Technology｜Official Document Management System - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74845"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-75482",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00622,
      "epss_percentile": 0.47159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SWE-agent",
      "product": "SWE-agent",
      "cwe": "CWE-22",
      "title": "SWE-agent Trajectory Inspector Path Traversal File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75482"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-38165",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00596,
      "epss_percentile": 0.45863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38165"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-67926",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00589,
      "epss_percentile": 0.45586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67926"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-67965",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00589,
      "epss_percentile": 0.45587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67965"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-50768",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00587,
      "epss_percentile": 0.45493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50768"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-67678",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00587,
      "epss_percentile": 0.45494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67678"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-67868",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00576,
      "epss_percentile": 0.44968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67868"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-39254",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00561,
      "epss_percentile": 0.44241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39254"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-39255",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00561,
      "epss_percentile": 0.44241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39255"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-65974",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00557,
      "epss_percentile": 0.44033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-1336",
      "title": "ERPNext: Server-Side Template Injection leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65974"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-71479",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.41966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-190",
      "title": "New API: Integer overflow in quota billing yields negative charges (self-crediting)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71479"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-16137",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00519,
      "epss_percentile": 0.41919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "ShareFile Storage Zones Controller",
      "cwe": "CWE-22",
      "title": "Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16137"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-75110",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00516,
      "epss_percentile": 0.41744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MemTensor",
      "product": "MemOS",
      "cwe": "CWE-697",
      "title": "MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75110"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-50772",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00515,
      "epss_percentile": 0.4168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50772"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-44845",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00501,
      "epss_percentile": 0.40853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jumpserver",
      "product": "jumpserver",
      "cwe": "CWE-1336",
      "title": "JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Applet Host Deployment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44845"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-47698",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00492,
      "epss_percentile": 0.40293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2: Sandbox Breakout Using Dangerous Host Proto Mutators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47698"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-71979",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "indilib",
      "product": "indi",
      "cwe": "CWE-121",
      "title": "INDI indiserver 2.2.4.2 Stack Buffer Overflow via XML Tag Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71979"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-57233",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0048,
      "epss_percentile": 0.39542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-22",
      "title": "Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57233"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-56685",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-78",
      "title": "Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56685"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-64868",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-400",
      "title": "New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64868"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-35219",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.3858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35219"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-64859",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00464,
      "epss_percentile": 0.38495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-200",
      "title": "New API: User List API Leaks Root User Access Token Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64859"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-74872",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0046,
      "epss_percentile": 0.38234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-426",
      "title": "openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74872"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2025-27621",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uptrain-ai",
      "product": "uptrain",
      "cwe": "CWE-287",
      "title": "UpTrain has a Constant Default API Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27621"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-67967",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67967"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-40506",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-22",
      "title": "OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40506"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-50775",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0044,
      "epss_percentile": 0.36835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50775"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-15218",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI (RHOAI)",
      "cwe": "CWE-266",
      "title": "Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts with excessive permissions lead to privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15218"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-56686",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-78",
      "title": "Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56686"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-59910",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-78",
      "title": "Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59910"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-74895",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.34224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-693",
      "title": "openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74895"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-68005",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68005"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-67966",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00407,
      "epss_percentile": 0.34116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67966"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-67917",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00406,
      "epss_percentile": 0.33952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanitization. This allows a remote attacker to escalate privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67917"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-67960",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67960"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-51346",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51346"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-67854",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.33017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67854"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-74886",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-184",
      "title": "openssl_encrypt before 1.4.0 Plugin Import Guard Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74886"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-19965",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00396,
      "epss_percentile": 0.32945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "automad",
      "cwe": "CWE-204",
      "title": "automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19965"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-59903",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00395,
      "epss_percentile": 0.32885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-524",
      "title": "Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59903"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-74894",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-287",
      "title": "openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74894"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-19979",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00393,
      "epss_percentile": 0.32674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "A1300",
      "cwe": "CWE-285",
      "title": "GL.iNet XE3000 WebDAV Service MOVE authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19979"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-19997",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00393,
      "epss_percentile": 0.32627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-639",
      "title": "Webkul Bagisto Backend Sales RMA Endpoint requests authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19997"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-75111",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "evidentlyai",
      "product": "evidently",
      "cwe": "CWE-22",
      "title": "Evidently UI Path Traversal via Dataset Materialization Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75111"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-74899",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.3216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-95",
      "title": "openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74899"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-71472",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-78",
      "title": "Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71472"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-74799",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.31829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-215",
      "title": "SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74799"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-71518",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typemill",
      "product": "typemill",
      "cwe": "CWE-863",
      "title": "Typemill < 2.26.0 Authorization Bypass via Media File Download Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71518"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-73646",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "postcss",
      "product": "postcss",
      "cwe": "CWE-22",
      "title": "PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73646"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-74238",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tier4",
      "product": "nebula",
      "cwe": "CWE-125",
      "title": "TIER IV Nebula 1.2.0 Heap Out-of-Bounds Read via VLP32 UDP Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74238"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-74868",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-307",
      "title": "SiYuan before 3.7.4 Brute-Force Authentication via Publish Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74868"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-65343",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A remote attacker may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65343"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-19968",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00373,
      "epss_percentile": 0.30546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Asset Import Library",
      "product": "Assimp",
      "cwe": "CWE-122",
      "title": "Open Asset Import Library Assimp 3DGS MDL7 Model LWOLoader.h ReadFaces_3DGS_MDL7 heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19968"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-74878",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-770",
      "title": "openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74878"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-74798",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00366,
      "epss_percentile": 0.29797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan kernel Path Traversal via database_clean MCP tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74798"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-19974",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00364,
      "epss_percentile": 0.29611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "treefrogframework",
      "product": "treefrog-framework",
      "cwe": "CWE-287",
      "title": "treefrogframework treefrog-framework Session Cookie tsessioncookiestore.cpp strncmp improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19974"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-64866",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00363,
      "epss_percentile": 0.29499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-862",
      "title": "New API: Admin can reset passkeys for same-level or higher-privileged users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64866"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-19971",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.29466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LB-Link",
      "product": "WR1210M",
      "cwe": "CWE-306",
      "title": "LB-Link WR1210M Backup Endpoint backup.cgi main missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19971"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-75012",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "EX1200L",
      "cwe": "CWE-404",
      "title": "TOTOLINK EX1200L Password Configuration cstecgi.cgi setPasswordCfg null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75012"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-75013",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "EX1200L",
      "cwe": "CWE-404",
      "title": "TOTOLINK EX1200L cstecgi.cgi setWizardCfg null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75013"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-75479",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeecgboot",
      "product": "jimureport",
      "cwe": "CWE-306",
      "title": "JimuReport Unauthenticated Report Listing and Share Token Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75479"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-54356",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-862",
      "title": "Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54356"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-42162",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00349,
      "epss_percentile": 0.2804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42162"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-19998",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00347,
      "epss_percentile": 0.27889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Shopping System",
      "cwe": "CWE-79",
      "title": "code-projects Online Shopping System offersmail.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19998"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-19996",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00344,
      "epss_percentile": 0.2754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-266",
      "title": "Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19996"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-63667",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-22",
      "title": "ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63667"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-71486",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-400",
      "title": "vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71486"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-19970",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00341,
      "epss_percentile": 0.27227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Asset Import Library",
      "product": "Assimp",
      "cwe": "CWE-122",
      "title": "Open Asset Import Library Assimp Node MDLLoader.cpp AddBonesToNodeGraph_3DGS_MDL7 heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19970"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-75006",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-918",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75006"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-50770",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.26988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50770"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-50774",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.26988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50774"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-71980",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BelledonneCommunications",
      "product": "bcg729",
      "cwe": "CWE-125",
      "title": "Belledonne Communications bcg729 1.1.2 Out-of-Bounds Read via decodeSIDframe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71980"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-61666",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faye",
      "product": "websocket-driver-ruby",
      "cwe": "CWE-248",
      "title": "websocket-driver: Denial of service via malformed Host header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61666"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-75103",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crawlab-team",
      "product": "crawlab",
      "cwe": "CWE-639",
      "title": "Crawlab Missing Authorization on Password Change Endpoint Allows Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75103"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-55674",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Cache poisoning/XSS via color scheme cookies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55674"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-74896",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-693",
      "title": "openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74896"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-74900",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-391",
      "title": "openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74900"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-50769",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00335,
      "epss_percentile": 0.26497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50769"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-42163",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42163"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-44846",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jumpserver",
      "product": "jumpserver",
      "cwe": "CWE-863",
      "title": "JumpServer: Privilege Overwrite via Organization Invite Logic Flaw",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44846"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-75014",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.2581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pet Grooming Management Software",
      "cwe": "CWE-89",
      "title": "SourceCodester Pet Grooming Management Software get_barcode_data.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75014"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-73523",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "COVESA",
      "product": "Open1722",
      "cwe": "CWE-197",
      "title": "COVESA Open1722 0.9.2 Stack Memory Disclosure via acf-can-listener.c Integer Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73523"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-75531",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pandora-analysis",
      "product": "pandora",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandora",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75531"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-74253",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00323,
      "epss_percentile": 0.25219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Sourcerer extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74253"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-45791",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-613",
      "title": "Dokploy: Password Change Does Not Revoke Active Sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45791"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-75000",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.2515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-669",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate \"by\" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75000"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-73560",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-918",
      "title": "vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73560"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-47686",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00315,
      "epss_percentile": 0.24334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47686"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-65976",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deskflow",
      "product": "deskflow",
      "cwe": "CWE-400",
      "title": "Deskflow: Clipboard receiver can accumulate data beyond Deskflow's configured clipboard size limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65976"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-12553",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "Web Jetadmin",
      "cwe": "CWE-787",
      "title": "HP Web Jetadmin (WJA) - Potential Arbitrary File Read/Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12553"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-71553",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.24046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-1321",
      "title": "ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71553"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-47683",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-770",
      "title": "vm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47683"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-42164",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42164"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-74880",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-598",
      "title": "openssl_encrypt before 1.4.0 Token Leakage via Query Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74880"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-65832",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deskflow",
      "product": "deskflow",
      "cwe": "CWE-125",
      "title": "Deskflow - Unauthenticated server-controlled out-of-bounds read in ServerProxy::setOptions / translateKey modifier-table indexing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65832"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-75003",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-669",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75003"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-74892",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-798",
      "title": "openssl_encrypt before 1.4.0 Hardcoded Secret Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74892"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-75106",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpnForm",
      "product": "OpnForm",
      "cwe": "CWE-340",
      "title": "OpnForm Editable Submission Secret Derivation via Empty Hashids Salt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75106"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-19992",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00305,
      "epss_percentile": 0.23241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Orange View Limited",
      "product": "DualSafe Password Manager & Digital Vault Extension",
      "cwe": "CWE-200",
      "title": "Orange View Limited DualSafe Password Manager & Digital Vault Extension postMessage-based Bridge information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19992"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-66792",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.2301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Global Hub",
      "cwe": "CWE-863",
      "title": "Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66792"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-65346",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65346"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-19987",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Best Employee Management System",
      "cwe": "CWE-548",
      "title": "SourceCodester Best Employee Management System Profile exposure of information through directory listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19987"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-75045",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00299,
      "epss_percentile": 0.22518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-288",
      "title": "In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75045"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-40126",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OutSystems",
      "product": "Service Center",
      "cwe": "CWE-79",
      "title": "DOM-based Cross-Site Scripting in OutSystems Service Center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40126"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-10080",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-704",
      "title": "Boards plugin panics on WebSocket command with non-string field types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10080"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-16467",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolusoft Software Technologies",
      "product": "Fortilogger",
      "cwe": "CWE-862",
      "title": "Broken Access Control in Dolusoft Software's Fortilogger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16467"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-19969",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00292,
      "epss_percentile": 0.21836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Asset Import Library",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Open Asset Import Library Assimp 3DGS MDL7 Model Output Mesh Generator MDLLoader.cpp GenerateOutputMeshes_3DGS_MDL7 buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19969"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-71424",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onyx-dot-app",
      "product": "onyx",
      "cwe": "CWE-200",
      "title": "Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71424"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-17639",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP Smart Tank 5101 All-in-One Printer",
      "cwe": "CWE-400",
      "title": "Certain HP Smart Tank All in One – Potential Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17639"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-74800",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.21402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.7.4 Stored XSS via assets endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74800"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-51977",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.21241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-321",
      "title": "An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51977"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-68762",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.2119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Ktor",
      "cwe": "CWE-835",
      "title": "In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68762"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-75004",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-77",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75004"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-63178",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onyx-dot-app",
      "product": "onyx",
      "cwe": "CWE-639",
      "title": "Onyx Curator-scope IDOR: any curator can modify membership of arbitrary user groups via unscoped PATCH /manage/admin/user-group/{id} and /add-users leading to cross-group document disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63178"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-19994",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00285,
      "epss_percentile": 0.21056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-639",
      "title": "Webkul Bagisto Configuration Management execute authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19994"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-74891",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-798",
      "title": "openssl_encrypt before 1.4.0 Hardcoded Database Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74891"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-45790",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-269",
      "title": "Dokploy: Invitation Role Escalation Allows Organization Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45790"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-75481",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "skypilot-org",
      "product": "skypilot",
      "cwe": "CWE-269",
      "title": "SkyPilot Authentication Bypass via Service Account Role Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75481"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-48053",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "learningequality",
      "product": "kolibri",
      "cwe": "CWE-918",
      "title": "Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48053"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-74254",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.20634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlack.fr",
      "product": "Page Builder CK extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74254"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-19693",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "max-mapper",
      "product": "extract-zip",
      "cwe": "CWE-59",
      "title": "extract-zip arbitrary file write outside the destination directory via a symlink at the final path component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19693"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-74881",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-942",
      "title": "openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74881"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-74234",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legora",
      "product": "Legora",
      "cwe": "CWE-95",
      "title": "Legora < 2026-08-14 XSS via Mermaid gray-matter JavaScript Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74234"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-59893",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andialbrecht",
      "product": "sqlparse",
      "cwe": "CWE-1333",
      "title": "sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59893"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-75010",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.2042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-669",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75010"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-33437",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stirling-Tools",
      "product": "Stirling-PDF",
      "cwe": "CWE-79",
      "title": "Stirling PDF: Stored XSS in Info Summary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33437"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-75077",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00278,
      "epss_percentile": 0.20382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75077"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-75105",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpipam",
      "product": "phpipam",
      "cwe": "CWE-639",
      "title": "phpIPAM Temporary Subnet Share Information Disclosure via Address Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75105"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-75529",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pandora-analysis",
      "product": "pandora",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandora",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75529"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-13700",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WooMS",
      "cwe": "CWE-918",
      "title": "WooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13700"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-19999",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.1979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Asset Import Library Assimp",
      "product": "Assimp",
      "cwe": "CWE-120",
      "title": "Open Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBoneTrafoKeys_3DGS_MDL7 buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19999"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-75078",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75078"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-45698",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "netatalk",
      "cwe": "CWE-191",
      "title": "Netatalk has Integer Underflow → Stack Buffer Overflow in deletedir()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45698"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-64715",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64715"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-56677",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-306",
      "title": "9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56677"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-19993",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.1943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-840",
      "title": "Webkul Bagisto RMA State Validation update-status behavioral workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19993"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-75081",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.1943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-840",
      "title": "Webkul Bagisto store behavioral workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75081"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-74998",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-79",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74998"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-74884",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-73",
      "title": "openssl_encrypt before 1.4.0 Path Traversal via plugin_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74884"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-54336",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jumpserver",
      "product": "jumpserver",
      "cwe": "CWE-22",
      "title": "JumpServer: KoKo Web Terminal SFTP Path Traversal on Authorized Asset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54336"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-74801",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-78",
      "title": "SiYuan before 3.7.4 Local Privilege Escalation via elevator.exe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74801"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-43667",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-617",
      "title": "A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43667"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-74893",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-798",
      "title": "openssl_encrypt before 1.4.0 JWT Token Forgery via Hardcoded Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74893"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-65822",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-89",
      "title": "ERPNext: SQL Injection in \"Inactive Customers\" report via unvalidated `doctype` filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65822"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-19967",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00264,
      "epss_percentile": 0.1849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Asset Import Library",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Open Asset Import Library Assimp File Compression.cpp decompressBlock heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19967"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-54284",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andialbrecht",
      "product": "sqlparse",
      "cwe": "CWE-407",
      "title": "sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54284"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-71491",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andialbrecht",
      "product": "sqlparse",
      "cwe": "CWE-400",
      "title": "sqlparse: Quadratic O(n²) DoS in group_comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71491"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-75079",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75079"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-75080",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75080"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-19988",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alaev",
      "product": "SEO Tools Extension",
      "cwe": "CWE-74",
      "title": "Alaev SEO Tools Extension Popup UI popup.html addDiv cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19988"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-13202",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenText",
      "product": "Opentext Directory Services",
      "cwe": "CWE-79",
      "title": "HTML Injection in OTDS Swagger UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13202"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-74842",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kira-Pgr",
      "product": "PromptShopMCP",
      "cwe": "CWE-918",
      "title": "Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74842"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-74877",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-639",
      "title": "openssl_encrypt before 1.4.0 Missing Ownership Verification via revoke_key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74877"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-67925",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67925"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-74879",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-209",
      "title": "openssl_encrypt before 1.4.0 Information Disclosure via /ready endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74879"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-75049",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75049"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-74869",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.1762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-862",
      "title": "stoatchat before 0.15.0 Missing Authorization via Subscribe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74869"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-63409",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deskflow",
      "product": "deskflow",
      "cwe": "CWE-125",
      "title": "Deskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63409"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-14832",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ShopSmart Loyalty for WooCommerce",
      "cwe": "CWE-639",
      "title": "ShopSmart Loyalty for WooCommerce <= 1.0.0 - Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14832"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-74883",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-693",
      "title": "openssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and io",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74883"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-57485",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stirling-Tools",
      "product": "Stirling-PDF",
      "cwe": "CWE-200",
      "title": "Stirling-PDF: Internal Service Account API Key Disclosure via Pipeline Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57485"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-68517",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-942",
      "title": "Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68517"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-64780",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64780"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-64781",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-20",
      "title": "The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64781"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-74874",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-338",
      "title": "openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74874"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-16138",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "ShareFile Storage Zones Controller",
      "cwe": "CWE-502",
      "title": "Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16138"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-11817",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-863",
      "title": "CVE-2026-11817 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11817"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-22072",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OPPO",
      "product": "OPPO Health",
      "cwe": "CWE-20",
      "title": "Arbitrary URL Loading in WebView Leading to Token Leakage Risk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22072"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-9859",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9859"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-19972",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.1664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewpatient.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19972"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-75007",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-77",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75007"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-9816",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Insufficient server-side validation of board member role fields permits privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9816"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-64657",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-89",
      "title": "Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64657"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-75109",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "determined-ai",
      "product": "determined",
      "cwe": "CWE-862",
      "title": "Determined Missing Authorization Check on Generic Task Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75109"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-64865",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-362",
      "title": "New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64865"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-19986",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00242,
      "epss_percentile": 0.15672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Adblock for Youtube Extension",
      "cwe": "CWE-285",
      "title": "Adblock for Youtube Extension Event Listener contentscript.js updateDynamicRules improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19986"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-74901",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0024,
      "epss_percentile": 0.15427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-347",
      "title": "openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74901"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-19650",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19650"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-50601",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Planet9 desktop application",
      "cwe": "CWE-798",
      "title": "Planet9 Hardcoded Credentials Vulnerability Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50601"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-14564",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00238,
      "epss_percentile": 0.15076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Innotim Software Telecommunications and Consulting Trade Ltd. Co.",
      "product": "Logsign SIEM",
      "cwe": "CWE-522",
      "title": "Sensitive Data Exposure in Innotim Software's Logsign SIEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14564"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-75480",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "volcengine",
      "product": "OpenViking",
      "cwe": "CWE-863",
      "title": "OpenViking Debug Vector Endpoints Multi-tenant Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75480"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-68520",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-200",
      "title": "Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68520"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-63670",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-79",
      "title": "ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63670"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-43794",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43794"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-19966",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00235,
      "epss_percentile": 0.147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeCanyon",
      "product": "TimeCamp Integration for CRM",
      "cwe": "CWE-639",
      "title": "CodeCanyon TimeCamp Integration for CRM Contact Information Update save_contact authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19966"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-18674",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.1462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong Inc.",
      "product": "Kong Mesh",
      "cwe": "CWE-345",
      "title": "Kong Mesh multi-zone: the global control plane attributes KDS-synced resources by an unvalidated in-band zone identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18674"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-16471",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolusoft Software Technologies",
      "product": "Sonlogger",
      "cwe": "CWE-862",
      "title": "Broken Access Control in Dolusoft Software's Sonlogger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16471"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-65330",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.1434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65330"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-65347",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.1434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-400",
      "title": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65347"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-75044",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75044"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-19980",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "A1300",
      "cwe": "CWE-94",
      "title": "GL.iNet XE3000 Language Update ui.update_langs code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19980"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-59829",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Review queue exposes flag-related private message excerpts to category group moderators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59829"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-74873",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-214",
      "title": "openssl_encrypt before 1.4.0 Password Exposure via CLI Argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74873"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-73424",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-441",
      "title": "Astro: Unauthenticated path override in the @astrojs/vercel ISR function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73424"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-63669",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-639",
      "title": "ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63669"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-69146",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow",
      "cwe": "CWE-862",
      "title": "MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69146"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-75051",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75051"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-16049",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "_GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API endpoints_",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16049"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-69148",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow",
      "cwe": "CWE-862",
      "title": "MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69148"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-64778",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-200",
      "title": "The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Visiting a maliciously crafted website may leak sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64778"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-66795",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-295",
      "title": "Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does not validate certificate subject, signername, or requester identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66795"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-74999",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-79",
      "title": "In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the \"Add to address book\" action was subject to stored XSS.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74999"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-71566",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00212,
      "epss_percentile": 0.11778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openshift-metal3",
      "product": "fakefish",
      "cwe": "CWE-306",
      "title": "KubeVirt backend is not authenticated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71566"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-74858",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jae-jae",
      "product": "fetcher-mcp",
      "cwe": "CWE-918",
      "title": "jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74858"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-19984",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jkawamoto",
      "product": "mcp-florence2",
      "cwe": "CWE-918",
      "title": "jkawamoto mcp-florence2 __init__.py get_images server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19984"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-74887",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00207,
      "epss_percentile": 0.11055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-338",
      "title": "openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74887"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-64787",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64787"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-75046",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75046"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-15623",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00203,
      "epss_percentile": 0.10651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Google SecOps (Chronicle SOAR)",
      "cwe": "CWE-89",
      "title": "Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15623"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-74876",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00201,
      "epss_percentile": 0.10419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-347",
      "title": "openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74876"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-74889",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00201,
      "epss_percentile": 0.10419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-326",
      "title": "openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74889"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-43795",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43795"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-64784",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.1039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-125",
      "title": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64784"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-65331",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-703",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65331"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-65332",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-703",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65332"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-65333",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.1039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65333"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-65334",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65334"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-65335",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65335"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-65336",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.1039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-20",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65336"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-65337",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-20",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65337"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-65338",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65338"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-65340",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.1039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-20",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65340"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-75048",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.1026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75048"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-19973",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-89",
      "title": "itsourcecode Hospital Management System viewpaymentreport.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19973"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-20000",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-89",
      "title": "itsourcecode Hospital Management System viewprescriptionrecord.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20000"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-71567",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openshift-metal3",
      "product": "fakefish",
      "cwe": "CWE-78",
      "title": "User-controlled variables inserted unescaped into shell scripts and Kubernetes manifests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71567"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-53960",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53960"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-16045",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Delegated OAuth tokens could revoke unrelated OAuth application authorizations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16045"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-65351",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-703",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65351"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-54758",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-121",
      "title": "Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54758"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-70412",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00194,
      "epss_percentile": 0.09444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "iDRAC9",
      "cwe": "CWE-1330",
      "title": "Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70412"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-19995",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-79",
      "title": "Webkul Bagisto RMA Message send-message cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19995"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-75104",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "transformers",
      "cwe": "CWE-22",
      "title": "Hugging Face Transformers Path Traversal via Checkpoint Index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75104"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-74875",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00188,
      "epss_percentile": 0.08806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-345",
      "title": "openssl_encrypt before 1.4.0 Schema Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74875"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-74870",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-532",
      "title": "openssl_encrypt before 1.4.8 Hardware Pepper Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74870"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-64779",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.0855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-362",
      "title": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64779"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-50771",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50771"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-75053",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-918",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75053"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-52886",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-22",
      "title": "Notepad++: session.xml backupFilePath starts_with Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52886"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-12630",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.07009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "6LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12630"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-28984",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28984"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-73410",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-367",
      "title": "Budibase: SSRF via DNS rebinding in the REST datasource integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73410"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-75108",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "next-terminal",
      "product": "next-terminal",
      "cwe": "CWE-862",
      "title": "Next Terminal Missing Per-Asset Authorization on Portal Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75108"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-16044",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Insufficient validation of guest board admin privileges on archive import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16044"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-19975",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0017,
      "epss_percentile": 0.06768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Azuriom",
      "product": "CMS",
      "cwe": "CWE-367",
      "title": "Azuriom CMS Money Transfer ProfileController.php transferMoney toctou",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19975"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-65329",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-287",
      "title": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65329"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-55704",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Shared-draft titles and excerpts leak through group post serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55704"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-74888",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-327",
      "title": "openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74888"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-65341",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65341"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-50773",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.0637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-427",
      "title": "An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50773"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-12629",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-835",
      "title": "PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12629"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-74890",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00165,
      "epss_percentile": 0.06277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-345",
      "title": "openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74890"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-12519",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12519"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-16047",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "Board channel linking without read channel permission validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16047"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-46345",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.0552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oscal-compass",
      "product": "compliance-trestle",
      "cwe": "CWE-22",
      "title": "compliance-trestle - jinja has an Arbitrary File Write via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46345"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-74579",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00157,
      "epss_percentile": 0.05368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nft_payload: fix mask build for partial field offload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74579"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-9693",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00156,
      "epss_percentile": 0.05279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-459",
      "title": "Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9693"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-10527",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Boards plugin retains Board Admin rights for users demoted to System Guest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10527"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-16048",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Channel member roles accept out-of-scope roles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16048"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-34398",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeCAD",
      "product": "FreeCAD",
      "cwe": "CWE-95",
      "title": "FreeCAD: Arbitrary Code Execution via eval() on untrusted project file metadata in BIM Workbench",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34398"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-75056",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-78",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75056"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-16046",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Missing run-state validation on finished playbook runs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16046"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-64782",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00151,
      "epss_percentile": 0.04806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-362",
      "title": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64782"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-15754",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.0467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15754"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-75060",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "PyCharm",
      "cwe": "CWE-306",
      "title": "In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75060"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-19589",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Packer",
      "cwe": "CWE-22",
      "title": "Packer vulnerable to arbitrary file write via crafted plugin archive during installation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19589"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-64788",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64788"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-75059",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "PyCharm",
      "cwe": "CWE-79",
      "title": "In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75059"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-68518",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-78",
      "title": "Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68518"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-62982",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-78",
      "title": "Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62982"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-34789",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeCAD",
      "product": "FreeCAD",
      "cwe": "CWE-94",
      "title": "FreeCAD: Arbitrary code execution via unsandboxed PyImport_ImportModule in PropertyPythonObject::Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34789"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-56089",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-35",
      "title": "Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56089"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-34399",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeCAD",
      "product": "FreeCAD",
      "cwe": "CWE-95",
      "title": "FreeCAD: Arbitrary Code Execution via eval() on untrusted SVG template scale field in BIM TechDraw Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34399"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-75057",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-532",
      "title": "In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75057"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-75052",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-77",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75052"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-65339",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-693",
      "title": "A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to leak sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65339"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-67961",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67961"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-74882",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-345",
      "title": "openssl_encrypt before 1.4.0 Insecure Default Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74882"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-59894",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.0297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andialbrecht",
      "product": "sqlparse",
      "cwe": "CWE-94",
      "title": "sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59894"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-68765",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hashcat",
      "product": "hashcat",
      "cwe": "CWE-122",
      "title": "hashcat KeePass KDBX v4 Module Heap Buffer Overflow via Token Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68765"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-56090",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-427",
      "title": "Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56090"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-68519",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-78",
      "title": "Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68519"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-74885",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00122,
      "epss_percentile": 0.02326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-117",
      "title": "openssl_encrypt before 1.4.0 Logging Bug and Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74885"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-75054",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-918",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75054"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-75055",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-611",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75055"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-75058",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-611",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75058"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-75483",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.0218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "romkatv",
      "product": "powerlevel10k",
      "cwe": "CWE-150",
      "title": "powerlevel10k Control Character Injection via package.json Version",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75483"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-64760",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.0212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak sensitive kernel state.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64760"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-59909",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-35",
      "title": "Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59909"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-65349",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to cause unexpected system termination or read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65349"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-59911",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-532",
      "title": "Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59911"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-40145",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeyondTrust",
      "product": "Endpoint Privilege Management (Windows deployment)",
      "cwe": "CWE-1220",
      "title": "Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40145"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-40144",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeyondTrust",
      "product": "Endpoint Privilege Management (Windows deployments)",
      "cwe": "CWE-125",
      "title": "Memory corruption vulnerability in Endpoint Privilege Management (Windows deployments)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40144"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-9771",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-822",
      "title": "Missing device-pointer validation in flash_copy() syscall allows userspace privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9771"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-75587",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00104,
      "epss_percentile": 0.01154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-200",
      "title": "Plaintext pre-auth secret exposure via Desktop App diagnostics report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75587"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-74802",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00104,
      "epss_percentile": 0.01156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-346",
      "title": "SiYuan 3.7.3 Cross-Site WebSocket Hijacking via network proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74802"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-74867",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-352",
      "title": "SiYuan before 3.7.4 Cross-Site Request Forgery via CheckAuth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74867"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-70495",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.01001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-269",
      "title": "Search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70495"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-50602",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Planet9 background service",
      "cwe": "CWE-732",
      "title": "Planet9 Incorrect Permission Assignment Vulnerability Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50602"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-71858",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-78",
      "title": "Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71858"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-74871",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-916",
      "title": "openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74871"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-49302",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-200",
      "title": "Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49302"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-49307",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-200",
      "title": "Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49307"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-58560",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-476",
      "title": "Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58560"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-58561",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-476",
      "title": "Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58561"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-49308",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-264",
      "title": "Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49308"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-49301",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00086,
      "epss_percentile": 0.00399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-200",
      "title": "Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49301"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-49304",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.0021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-264",
      "title": "Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49304"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-49305",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-755",
      "title": "Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49305"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-49306",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0008,
      "epss_percentile": 0.00207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-416",
      "title": "UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49306"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-49303",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-264",
      "title": "Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49303"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2025-62593",
      "detail": "ADDED TO KEV — CVE-2025-62593 (ray-project ray). Remediation due August 20, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2018-8727",
      "detail": "EXPLOIT PUBLISHED — CVE-2018-8727. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-10869",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-10869. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-23368",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-23368 (wildfly-core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24842 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-27606",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-27606 (rollup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-27727",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-27727 (swaldman mchange-commons-java). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-27962",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-27962 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28498",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28498 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28802",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28802 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29074",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29074 (svgo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32597",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32597 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35172",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35172 (distribution). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40938",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40938 (tektoncd pipeline). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41134",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41134 (microsoft kiota). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42041 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42880",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42880 (argoproj argo-cd). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42945",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4598",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4598 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4599",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4599 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4600",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4600 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4601",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4601 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4602",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4602 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-6931",
      "detail": "RESCORED — CVE-2023-6931 (Linux Kernel). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-6666",
      "detail": "RESCORED — CVE-2025-6666 (motogadget mo.lock Ignition Lock). CVSS 1 → 0.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-15370",
      "detail": "RESCORED — CVE-2026-15370 (Red Hat Enterprise Linux 10). CVSS 6.7 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16713",
      "detail": "RESCORED — CVE-2026-16713 (IBM Documentation Offline). CVSS 4.3 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16929",
      "detail": "RESCORED — CVE-2026-16929 (IBM i). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19895",
      "detail": "RESCORED — CVE-2026-19895 (opensourcepos Open Source Point of Sale). CVSS 6.3 → 2.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19897",
      "detail": "RESCORED — CVE-2026-19897 (mangroup dtale). CVSS 6.3 → 2.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19900",
      "detail": "RESCORED — CVE-2026-19900 (LB-LINK X-PRO). CVSS 9.2 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19903",
      "detail": "RESCORED — CVE-2026-19903 (SourceCodester Online Clothing Store). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19917",
      "detail": "RESCORED — CVE-2026-19917 (code-projects Online Food Order System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19920",
      "detail": "RESCORED — CVE-2026-19920 (code-projects Online Shopping System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19922",
      "detail": "RESCORED — CVE-2026-19922 (code-projects Online Shopping System). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19925",
      "detail": "RESCORED — CVE-2026-19925 (SourceCodester Stock Management System). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19927",
      "detail": "RESCORED — CVE-2026-19927 (OpenBoxes). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19930",
      "detail": "RESCORED — CVE-2026-19930 (Dolibarr). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19933",
      "detail": "RESCORED — CVE-2026-19933 (DefaultFuction Customer-Relationship-Management-In-C-Project). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19958",
      "detail": "RESCORED — CVE-2026-19958 (iatsiuk pptr-mcp). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19961",
      "detail": "RESCORED — CVE-2026-19961 (Edimax EW-7478APC). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19962",
      "detail": "RESCORED — CVE-2026-19962 (Edimax EW-7478APC). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19963",
      "detail": "RESCORED — CVE-2026-19963 (Edimax EW-7478APC). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19964",
      "detail": "RESCORED — CVE-2026-19964 (Jij-Inc Jij-MCP-Server). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-2100",
      "detail": "RESCORED — CVE-2026-2100 (p11-glue p11-kit). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-2332",
      "detail": "RESCORED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). CVSS 7.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-32591",
      "detail": "RESCORED — CVE-2026-32591 (Red Hat Quay 3.1). CVSS 5.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33216",
      "detail": "RESCORED — CVE-2026-33216 (nats-io nats-server). CVSS 8.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33217",
      "detail": "RESCORED — CVE-2026-33217 (nats-io nats-server). CVSS 7.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33247",
      "detail": "RESCORED — CVE-2026-33247 (nats-io nats-server). CVSS 7.4 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33997",
      "detail": "RESCORED — CVE-2026-33997 (moby). CVSS 6.8 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-35425",
      "detail": "RESCORED — CVE-2026-35425 (Microsoft Azure API Management (APIM)). CVSS 8 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-40938",
      "detail": "RESCORED — CVE-2026-40938 (tektoncd pipeline). CVSS 7.5 → 8.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42041",
      "detail": "RESCORED — CVE-2026-42041 (axios). CVSS 4.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4598",
      "detail": "RESCORED — CVE-2026-4598 (jsrsasign). CVSS 8.7 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-45998",
      "detail": "RESCORED — CVE-2026-45998 (Linux). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4600",
      "detail": "RESCORED — CVE-2026-4600 (jsrsasign). CVSS 9.1 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4601",
      "detail": "RESCORED — CVE-2026-4601 (jsrsasign). CVSS 9.4 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4602",
      "detail": "RESCORED — CVE-2026-4602 (jsrsasign). CVSS 8.7 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-46579",
      "detail": "RESCORED — CVE-2026-46579 (Red Hat OpenShift Container Platform 4.12). CVSS 7.4 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4878",
      "detail": "RESCORED — CVE-2026-4878 (Red Hat Enterprise Linux 10). CVSS 6.7 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-52972",
      "detail": "RESCORED — CVE-2026-52972 (Linux). CVSS 7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-53059",
      "detail": "RESCORED — CVE-2026-53059 (Linux). CVSS 6.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57104",
      "detail": "RESCORED — CVE-2026-57104 (Microsoft Azure Storage Explorer). CVSS 8.8 → 9.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58010",
      "detail": "RESCORED — CVE-2026-58010 (GNOME GLib). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58011",
      "detail": "RESCORED — CVE-2026-58011 (GNOME GLib). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58012",
      "detail": "RESCORED — CVE-2026-58012 (GNOME GLib). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58013",
      "detail": "RESCORED — CVE-2026-58013 (GNOME GLib). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58014",
      "detail": "RESCORED — CVE-2026-58014 (GNOME GLib). CVSS 7.3 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58015",
      "detail": "RESCORED — CVE-2026-58015 (GNOME GLib). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58612",
      "detail": "RESCORED — CVE-2026-58612 (Microsoft PowerShell 7.4). CVSS 7.4 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59845",
      "detail": "RESCORED — CVE-2026-59845 (Red Hat Enterprise Linux 10). CVSS 5.3 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59847",
      "detail": "RESCORED — CVE-2026-59847 (Red Hat Enterprise Linux 10). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59850",
      "detail": "RESCORED — CVE-2026-59850 (Red Hat Enterprise Linux 10). CVSS 4.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65675",
      "detail": "RESCORED — CVE-2026-65675 (Microsoft Visual Studio Code CoPilot Chat Extension). CVSS 7.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65799",
      "detail": "RESCORED — CVE-2026-65799 (Microsoft Windows 10 Version 1607). CVSS 6.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65813",
      "detail": "RESCORED — CVE-2026-65813 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70304",
      "detail": "RESCORED — CVE-2026-70304 (Microsoft Windows 10 Version 1607). CVSS 6.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70340",
      "detail": "RESCORED — CVE-2026-70340 (Microsoft Azure CycleCloud 8.9.1). CVSS 8.1 → 8.8 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2018-8727",
      "detail": "ENRICHED — CVE-2018-8727. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2019-10869",
      "detail": "ENRICHED — CVE-2019-10869. Received CVSS 8.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53325",
      "detail": "ENRICHED — CVE-2026-53325 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53382",
      "detail": "ENRICHED — CVE-2026-53382 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53385",
      "detail": "ENRICHED — CVE-2026-53385 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53393",
      "detail": "ENRICHED — CVE-2026-53393 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53403",
      "detail": "ENRICHED — CVE-2026-53403 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-63794",
      "detail": "ENRICHED — CVE-2026-63794 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-63798",
      "detail": "ENRICHED — CVE-2026-63798 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-63804",
      "detail": "ENRICHED — CVE-2026-63804 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64187",
      "detail": "ENRICHED — CVE-2026-64187 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64192",
      "detail": "ENRICHED — CVE-2026-64192 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64205",
      "detail": "ENRICHED — CVE-2026-64205 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64207",
      "detail": "ENRICHED — CVE-2026-64207 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64244",
      "detail": "ENRICHED — CVE-2026-64244 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64245",
      "detail": "ENRICHED — CVE-2026-64245 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64246",
      "detail": "ENRICHED — CVE-2026-64246 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64248",
      "detail": "ENRICHED — CVE-2026-64248 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64249",
      "detail": "ENRICHED — CVE-2026-64249 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64250",
      "detail": "ENRICHED — CVE-2026-64250 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64252",
      "detail": "ENRICHED — CVE-2026-64252 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64253",
      "detail": "ENRICHED — CVE-2026-64253 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64254",
      "detail": "ENRICHED — CVE-2026-64254 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64256",
      "detail": "ENRICHED — CVE-2026-64256 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64258",
      "detail": "ENRICHED — CVE-2026-64258 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64262",
      "detail": "ENRICHED — CVE-2026-64262 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64263",
      "detail": "ENRICHED — CVE-2026-64263 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64264",
      "detail": "ENRICHED — CVE-2026-64264 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64267",
      "detail": "ENRICHED — CVE-2026-64267 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64270",
      "detail": "ENRICHED — CVE-2026-64270 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64271",
      "detail": "ENRICHED — CVE-2026-64271 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64272",
      "detail": "ENRICHED — CVE-2026-64272 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64273",
      "detail": "ENRICHED — CVE-2026-64273 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64274",
      "detail": "ENRICHED — CVE-2026-64274 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64275",
      "detail": "ENRICHED — CVE-2026-64275 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64278",
      "detail": "ENRICHED — CVE-2026-64278 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64282",
      "detail": "ENRICHED — CVE-2026-64282 (Linux). Received CVSS 4.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64283",
      "detail": "ENRICHED — CVE-2026-64283 (Linux). Received CVSS 7.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64285",
      "detail": "ENRICHED — CVE-2026-64285 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64288",
      "detail": "ENRICHED — CVE-2026-64288 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64289",
      "detail": "ENRICHED — CVE-2026-64289 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64290",
      "detail": "ENRICHED — CVE-2026-64290 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64291",
      "detail": "ENRICHED — CVE-2026-64291 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64292",
      "detail": "ENRICHED — CVE-2026-64292 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64294",
      "detail": "ENRICHED — CVE-2026-64294 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64295",
      "detail": "ENRICHED — CVE-2026-64295 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64297",
      "detail": "ENRICHED — CVE-2026-64297 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
