{
  "day": "2026-08-18",
  "boundary": "UTC calendar day",
  "published_count": 1407,
  "by_severity": {
    "CRITICAL": 211,
    "HIGH": 731,
    "MEDIUM": 373,
    "LOW": 60
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 32,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-75094",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02086,
      "epss_percentile": 0.8006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "COMFAST",
      "product": "CF-N1-S",
      "cwe": "CWE-77",
      "title": "COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75094"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-24301",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0163,
      "epss_percentile": 0.7429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Copilot Web",
      "cwe": "CWE-77",
      "title": "Microsoft Copilot Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24301"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-15748",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01177,
      "epss_percentile": 0.65131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-434",
      "title": "Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15748"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-63639",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01171,
      "epss_percentile": 0.64939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valkey-io",
      "product": "valkey",
      "cwe": "CWE-416",
      "title": "Valkey: UAF in stream deserialization may lead to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63639"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-75854",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01069,
      "epss_percentile": 0.62162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-306",
      "title": "ArcadeDB Redis Wire-Protocol Plugin Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75854"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-75784",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01021,
      "epss_percentile": 0.60708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-WLC100",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75784"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-56684",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00889,
      "epss_percentile": 0.56538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valkey-io",
      "product": "valkey",
      "cwe": "CWE-416",
      "title": "Valkey: TLS pending-data processing use-after-free may allow remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56684"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-59940",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00813,
      "epss_percentile": 0.54168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxsmnsyc",
      "product": "seroval",
      "cwe": "CWE-502",
      "title": "Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59940"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-73343",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00801,
      "epss_percentile": 0.53785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AresIT",
      "product": "WP Compress",
      "cwe": "CWE-94",
      "title": "WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73343"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-45117",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00793,
      "epss_percentile": 0.53533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-94",
      "title": "MyBB: Installer database configuration RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45117"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-75872",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00709,
      "epss_percentile": 0.50691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maalfer",
      "product": "MailerUp",
      "cwe": "CWE-80",
      "title": "HTML Injection in MailerUp double opt-in verification email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75872"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-66046",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00677,
      "epss_percentile": 0.49498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat project",
      "product": "libexpat",
      "cwe": "CWE-407",
      "title": "Expat Denial of Service via storeAtts() Quadratic Complexity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66046"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-70415",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00652,
      "epss_percentile": 0.48479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-120",
      "title": "Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70415"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-75976",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00627,
      "epss_percentile": 0.47349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-823DRU",
      "cwe": "CWE-121",
      "title": "TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75976"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-67443",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00622,
      "epss_percentile": 0.47164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-862",
      "title": "FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67443"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-53457",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00622,
      "epss_percentile": 0.47114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ha-china",
      "product": "blueprint-studio",
      "cwe": "CWE-22",
      "title": "Blueprint Studio terminal command working directory not bounded to config directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53457"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-75877",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00614,
      "epss_percentile": 0.46745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TV-IP751WIC",
      "cwe": "CWE-119",
      "title": "TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75877"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-54348",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00611,
      "epss_percentile": 0.46598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-89",
      "title": "Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54348"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-75827",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00589,
      "epss_percentile": 0.45565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav before 2.0.15 Arbitrary File Write via error_log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75827"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-62988",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00585,
      "epss_percentile": 0.45408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-200",
      "title": "Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62988"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-66793",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00574,
      "epss_percentile": 0.44885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-20",
      "title": "Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via managedclusteraddon annotation enables rce on spoke",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66793"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-74990",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00557,
      "epss_percentile": 0.44028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74990"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-50142",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00556,
      "epss_percentile": 0.43947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-190",
      "title": "libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50142"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-62292",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00538,
      "epss_percentile": 0.43029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif: Out-of-bounds read in uncompressed unci tile range slicing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62292"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-73366",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Easy Google Maps",
      "cwe": "CWE-502",
      "title": "WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73366"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-73380",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Popup by Supsystic",
      "cwe": "CWE-502",
      "title": "WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73380"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-75773",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00524,
      "epss_percentile": 0.42265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "karakeep-app",
      "product": "karakeep",
      "cwe": "CWE-307",
      "title": "karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75773"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-60672",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60672"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-60696",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60696"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-60698",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60698"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-60858",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60858"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-60977",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60977"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-61318",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.4211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61318"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-62626",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62626"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-62632",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62632"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-62633",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.4211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62633"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-62635",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.4211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62635"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-70926",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": null,
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70926"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-18929",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0052,
      "epss_percentile": 0.41975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Carbone",
      "product": "Carbone",
      "cwe": "CWE-409",
      "title": "Resource Exhaustion in Carbone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18929"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-75090",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00515,
      "epss_percentile": 0.41677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EricLBuehler",
      "product": "Mistral.rs",
      "cwe": "CWE-119",
      "title": "EricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_tokenizer out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75090"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-73381",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00511,
      "epss_percentile": 0.41451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Popup by Supsystic",
      "cwe": "CWE-288",
      "title": "WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73381"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-17084",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00511,
      "epss_percentile": 0.41409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-436",
      "title": "stringprep.map_table_b2() deviates from RFC 3454 Table B.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17084"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-60728",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60728"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-73502",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00507,
      "epss_percentile": 0.41187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkin",
      "product": "kin-openapi",
      "cwe": "CWE-476",
      "title": "kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73502"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-75897",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00504,
      "epss_percentile": 0.4103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSearch",
      "product": "OpenSearch Dashboards",
      "cwe": "CWE-1284",
      "title": "Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75897"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-75915",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00504,
      "epss_percentile": 0.41023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-200",
      "title": "CodeWhale before 0.8.64 Environment Variable Leak via js_execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75915"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-70820",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00499,
      "epss_percentile": 0.40737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Call Center Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70820"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-50187",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00494,
      "epss_percentile": 0.40434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohmyzsh",
      "product": "ohmyzsh",
      "cwe": "CWE-94",
      "title": "Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious .env files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50187"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-67440",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0049,
      "epss_percentile": 0.40177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-862",
      "title": "FUXA: Unauthenticated Socket.IO read events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67440"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-47720",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0049,
      "epss_percentile": 0.40201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-89",
      "title": "FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47720"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-61003",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00489,
      "epss_percentile": 0.40135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Managed File Transfer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61003"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-19500",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SureForms",
      "product": "SureForms",
      "cwe": "CWE-400",
      "title": "SureForms contains an uncontrolled resource consumption vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19500"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-60721",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60721"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-60727",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60727"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-60782",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60782"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-60821",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60821"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-60921",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60921"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-60946",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60946"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-60947",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60947"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-60958",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60958"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-60970",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60970"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-62457",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62457"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-62544",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62544"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-62592",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62592"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-62609",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62609"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-62611",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62611"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-62614",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62614"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-62617",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62617"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-62621",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62621"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-62622",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62622"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-62624",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62624"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-62630",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62630"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-62634",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62634"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-62639",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62639"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-62640",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62640"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-70689",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Essbase",
      "cwe": null,
      "title": "Vulnerability in Oracle Essbase (component: Infrastructure). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70689"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-70739",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.3995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70739"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-70740",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70740"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-70745",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.3995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70745"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-70817",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.3995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70817"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-70873",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70873"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-70905",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SAML to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70905"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-70970",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70970"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-71040",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71040"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-71074",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71074"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-71152",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71152"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-71164",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71164"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-60754",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60754"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-47719",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.39777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-918",
      "title": "FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47719"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-74012",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Steve Burge",
      "product": "TaxoPress",
      "cwe": "CWE-502",
      "title": "WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74012"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-73181",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeComplete",
      "product": "Extra Product Options & Add-Ons for WooCommerce",
      "cwe": "CWE-22",
      "title": "WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73181"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-60702",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60702"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-61206",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61206"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-61317",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61317"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-70920",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.39497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70920"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-60716",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60716"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-60722",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60722"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-60731",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60731"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-60751",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60751"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-60976",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scripting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60976"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-61276",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61276"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-70710",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales Foundation",
      "cwe": null,
      "title": "Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Suite (component: Security API). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Sales Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70710"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-70729",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Teleservice",
      "cwe": null,
      "title": "Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Request Form). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of this vulnerability can result in takeover of Oracle Teleservice. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70729"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-70737",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager for Systems Infrastructure",
      "cwe": null,
      "title": "Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70737"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-70747",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customers Online",
      "cwe": null,
      "title": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Customer Tab). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in takeover of Oracle Customers Online. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70747"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-70813",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Call Center Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70813"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-70918",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Hub",
      "cwe": null,
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70918"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-70922",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financial Services Enterprise Case Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70922"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-71878",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GBIF",
      "product": "Integrated Publishing Toolkit",
      "cwe": "CWE-306",
      "title": "Authentication bypass in Integrated Publishing Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71878"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-71879",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GBIF",
      "product": "Integrated Publishing Toolkit",
      "cwe": "CWE-288",
      "title": "Authentication bypass in Integrated Publishing Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71879"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-63643",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00474,
      "epss_percentile": 0.39173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MagicMirrorOrg",
      "product": "MagicMirror",
      "cwe": "CWE-441",
      "title": "MagicMirror: ssrf calendar .js",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63643"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-70854",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70854"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-65984",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-613",
      "title": "FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65984"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-70876",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00465,
      "epss_percentile": 0.38578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70876"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-60883",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60883"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-70735",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Profitability and Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70735"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-70781",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Proposals",
      "cwe": null,
      "title": "Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Proposals. Successful attacks of this vulnerability can result in takeover of Oracle Proposals. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70781"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-70861",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects Brazil",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70861"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-70939",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70939"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-70950",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70950"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-71099",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71099"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-75774",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00465,
      "epss_percentile": 0.38564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "karakeep-app",
      "product": "karakeep",
      "cwe": "CWE-287",
      "title": "karakeep-app karakeep OAuth Sign-In auth.ts improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75774"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-67271",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-787",
      "title": "Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67271"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-70700",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payables",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payables. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Payables. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70700"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-59949",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0046,
      "epss_percentile": 0.38267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yawkat",
      "product": "lz4-java",
      "cwe": "CWE-476",
      "title": "yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59949"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-75852",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00451,
      "epss_percentile": 0.37655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-306",
      "title": "ArcadeDB MongoDB wire protocol authentication bypass cross-database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75852"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-32474",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpWax",
      "product": "Templatiq",
      "cwe": "CWE-434",
      "title": "WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32474"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-60720",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60720"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-60730",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60730"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-62512",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62512"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-62588",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62588"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-62608",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via CORBA to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62608"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-66627",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EDGE22 Studios Ltd.",
      "product": "GP Premium",
      "cwe": "CWE-434",
      "title": "WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66627"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-60715",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60715"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-60726",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60726"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-60729",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60729"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-60767",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60767"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-60879",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60879"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-61002",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SOA Suite",
      "cwe": null,
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61002"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-61017",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61017"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-61022",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61022"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-61032",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61032"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-61040",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61040"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-61058",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61058"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-61118",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61118"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-61284",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": null,
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61284"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-61319",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle U.S. Federal Financials",
      "cwe": null,
      "title": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials. Successful attacks of this vulnerability can result in takeover of Oracle U.S. Federal Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61319"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-61330",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61330"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-61341",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61341"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-62450",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Flow Manufacturing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62450"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-62500",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62500"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-62612",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62612"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-70686",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.3733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": null,
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70686"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-70688",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Essbase",
      "cwe": null,
      "title": "Vulnerability in Oracle Essbase (component: Calculator). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70688"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-70742",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70742"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-70761",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Risk Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management. Successful attacks of this vulnerability can result in takeover of Oracle Risk Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70761"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-70818",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.3733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70818"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-70821",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.3733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70821"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-70863",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": null,
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70863"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-70877",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70877"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-70886",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70886"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-70928",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.3733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70928"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-70940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70940"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-70944",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70944"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-70948",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Purchasing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70948"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-70949",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70949"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-70966",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70966"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-71039",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71039"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-71055",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71055"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-71067",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71067"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-52736",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-459",
      "title": "ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52736"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-61302",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61302"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-70743",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70743"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-75627",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.37021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bastillion-io",
      "product": "Bastillion",
      "cwe": "CWE-288",
      "title": "Bastillion Authentication Bypass via Path-Prefix Routing Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75627"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-57580",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-436",
      "title": "authentik: Account Takeover via SAML NameID Comment Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57580"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-60591",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality Simphony",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60591"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-62638",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62638"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-70977",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70977"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-70981",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70981"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-70984",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70984"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-71102",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Portable Clusterware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Portable Clusterware. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71102"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-75935",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon Ion",
      "product": "Amazon Ion Java",
      "cwe": "CWE-789",
      "title": "Memory-amplification denial of service via declared-length preallocation in Amazon ion-java",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75935"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-75936",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon Ion",
      "product": "Amazon Ion Java",
      "cwe": "CWE-409",
      "title": "Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75936"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-70906",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": null,
      "title": "Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70906"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-70908",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70908"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-70927",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": null,
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Workflow. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70927"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-71113",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71113"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-71153",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71153"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-73927",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73927"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-73936",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73936"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-73997",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Starter Templates by Kadence WP",
      "cwe": "CWE-770",
      "title": "WordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73997"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-32444",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cwicly",
      "product": "Cwicly",
      "cwe": "CWE-94",
      "title": "WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32444"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-44472",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00439,
      "epss_percentile": 0.36717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saleor",
      "product": "saleor",
      "cwe": "CWE-287",
      "title": "Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44472"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-47627",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00435,
      "epss_percentile": 0.36462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-22",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47627"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-73400",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "Restaurant Menu by MotoPress",
      "cwe": "CWE-98",
      "title": "WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73400"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-50186",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RARgames",
      "product": "4gaBoards",
      "cwe": "CWE-22",
      "title": "4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50186"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-52854",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.3618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ProfessionalWiki",
      "product": "Maps",
      "cwe": "CWE-79",
      "title": "mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52854"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-52829",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-617",
      "title": "ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52829"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-76039",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00432,
      "epss_percentile": 0.3615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76039"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-76040",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76040"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-75874",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00429,
      "epss_percentile": 0.35971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Sandbox escape in the Remote Settings Client component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75874"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-54543",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.35892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-74",
      "title": "Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54543"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-70921",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00427,
      "epss_percentile": 0.3578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70921"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-60737",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00427,
      "epss_percentile": 0.3578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Web Services Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Web Services Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60737"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-71166",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.35666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71166"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-60796",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60796"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-70909",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70909"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-70952",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70952"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-49224",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb post revision authorization bypass allows Authors to read, restore, or delete other Authors' post revisions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49224"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-49225",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb product revision authorization bypass allows Vendors to read, restore, or delete other Vendors' product revisions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49225"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-50167",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kurrier-org",
      "product": "kurrier",
      "cwe": "CWE-639",
      "title": "Kurrier: Authenticated cross-user authorization bypass in Kurrier API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50167"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-48798",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sshnet",
      "product": "SSH.NET",
      "cwe": "CWE-22",
      "title": "SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48798"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-70770",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Warehouse Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Warehouse Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Warehouse Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70770"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-68924",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00417,
      "epss_percentile": 0.34919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MobSF",
      "product": "Mobile-Security-Framework-MobSF",
      "cwe": "CWE-400",
      "title": "MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68924"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-60699",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60699"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-62586",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Administration",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Administration. While the vulnerability is in Siebel CRM Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62586"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-62550",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62550"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-62554",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62554"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-70752",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70752"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-70772",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Warehouse Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70772"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-70799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SDP Number Portability",
      "cwe": null,
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SDP Number Portability accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70799"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-70822",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70822"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-70832",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70832"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-70889",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70889"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-70891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70891"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-76036",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00414,
      "epss_percentile": 0.34745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76036"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-76034",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76034"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-75859",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-22",
      "title": "CodeWhale before 0.8.64 Arbitrary File Read via instructions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75859"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-75914",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-22",
      "title": "CodeWhale before 0.8.64 Path Traversal via image_analyze symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75914"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-70722",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.3463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Inbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70722"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-62455",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62455"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-47606",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00409,
      "epss_percentile": 0.34216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-36",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47606"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-62629",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00408,
      "epss_percentile": 0.34202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized read access to a subset of Oracle Reports Developer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62629"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-60707",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60707"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-61332",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61332"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-73937",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon and unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73937"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-62377",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00408,
      "epss_percentile": 0.34148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-617",
      "title": "libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62377"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-60680",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60680"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-60779",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Marketing accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60779"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-60992",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60992"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-61265",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Orchestrator",
      "cwe": null,
      "title": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61265"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-70675",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70675"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-70684",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": null,
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70684"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-70704",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Trading Community",
      "cwe": null,
      "title": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in takeover of Oracle Trading Community. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70704"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-70814",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Call Center Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70814"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-70924",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Web Services Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Web Services Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70924"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-70931",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": null,
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Workflow accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Workflow. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70931"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-70959",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70959"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-71042",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71042"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-45734",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-837",
      "title": "MyBB: Default CAPTCHA missing invalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45734"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-75783",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-WLC100P",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75783"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-69219",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-789",
      "title": "RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69219"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-69220",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-674",
      "title": "RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69220"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-73399",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00399,
      "epss_percentile": 0.33343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flutterwave",
      "product": "Flutterwave WooCommerce",
      "cwe": "CWE-288",
      "title": "WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73399"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-61008",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61008"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-70730",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Profitability and Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70730"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-70741",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.3315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70741"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-70884",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70884"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-70978",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70978"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-71015",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71015"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-71026",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71026"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-73866",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73866"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-73916",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73916"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-73917",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73917"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-62599",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Trading Community",
      "cwe": null,
      "title": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. While the vulnerability is in Oracle Trading Community, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62599"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-62628",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62628"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-70721",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Profitability and Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. While the vulnerability is in Oracle Hyperion Profitability and Cost Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70721"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-60391",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60391"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-60393",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60393"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-60590",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality Simphony",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60590"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-60850",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60850"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-60889",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60889"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-60906",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60906"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-60914",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60914"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-61007",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61007"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-70810",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scripting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70810"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-70896",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70896"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-70910",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70910"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-70986",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70986"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-70987",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70987"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-71034",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71034"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-71107",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": null,
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71107"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-71142",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Unified Inventory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component). Supported versions that are affected are 7.5.0-7.5.1, 7.6.0-7.8.0 and 8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71142"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-71158",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71158"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-73878",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73878"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-73883",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73883"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-73884",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.3315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73884"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-73907",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73907"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-73938",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73938"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-70680",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications DBA",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Applications DBA. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70680"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-73350",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PSM Plugins",
      "product": "SupportCandy",
      "cwe": "CWE-266",
      "title": "WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73350"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-76038",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76038"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-52739",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-248",
      "title": "ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52739"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-62289",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-191",
      "title": "libheif: Integer underflow in Fraction constructor via double clap transform application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62289"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-75853",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-862",
      "title": "ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75853"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-71079",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00393,
      "epss_percentile": 0.32674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71079"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-62684",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00393,
      "epss_percentile": 0.32584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-200",
      "title": "File Browser: Share API exposes the password hash and bypass token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62684"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-62463",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62463"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-70958",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70958"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-62619",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62619"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-71106",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality OPERA 5 Property Services",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.28.0-5.6.28.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71106"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-62477",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62477"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-62491",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Purchasing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62491"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-62502",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62502"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-70701",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payables",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payables. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payables accessible data as well as unauthorized access to critical data or complete access to all Oracle Payables accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70701"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-70762",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Risk Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Risk Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Risk Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70762"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-70811",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Purchasing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70811"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-70815",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Internet Procurement Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70815"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-70835",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iRecruitment",
      "cwe": null,
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70835"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-70878",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70878"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-70881",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70881"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-70925",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70925"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-18963",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00391,
      "epss_percentile": 0.32375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-640",
      "title": "Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18963"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-75855",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-22",
      "title": "ArcadeDB before 26.8.1 Path Traversal via create/drop database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75855"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-71095",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71095"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-21582",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Atlassian",
      "product": "Crowd Data Center",
      "cwe": null,
      "title": "This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). This vulnerability was reported via our Penetration Testing program.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21582"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-76043",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-682",
      "title": "Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76043"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-76047",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76047"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-32470",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roxnor",
      "product": "FundEngine",
      "cwe": "CWE-502",
      "title": "WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32470"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-73341",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metagauss",
      "product": "RegistrationMagic",
      "cwe": "CWE-502",
      "title": "WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73341"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-73376",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Ultimate Maps by Supsystic",
      "cwe": "CWE-502",
      "title": "WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73376"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-73397",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Youzify",
      "product": "Youzify",
      "cwe": "CWE-502",
      "title": "WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73397"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-70690",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": null,
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70690"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-70802",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Human Resources",
      "cwe": null,
      "title": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Human Resources. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70802"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-62475",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Shipping Execution",
      "cwe": null,
      "title": "Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Shipping Execution. Successful attacks of this vulnerability can result in takeover of Oracle Shipping Execution. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62475"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-61011",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.3184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61011"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-61016",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.3184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61016"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-73396",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MakeWebBetter",
      "product": "MWB HubSpot for WooCommerce",
      "cwe": "CWE-288",
      "title": "WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73396"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-53533",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00385,
      "epss_percentile": 0.31809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cole",
      "product": "aiosmtplib",
      "cwe": "CWE-77",
      "title": "aiosmtplib: SMTP command injection via CR/LF in sender/recipient address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53533"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-71161",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00385,
      "epss_percentile": 0.3184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71161"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-61241",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Internet Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61241"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-61258",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Internet Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61258"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-70669",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70669"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-45118",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-83",
      "title": "MyBB: Contact page reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45118"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-50161",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baresip",
      "product": "re",
      "cwe": "CWE-190",
      "title": "libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50161"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-62357",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dragonflydb",
      "product": "dragonfly",
      "cwe": "CWE-190",
      "title": "DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62357"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-60592",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Cluster",
      "cwe": null,
      "title": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60592"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-73930",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.3162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73930"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-73187",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gingerplugins",
      "product": "Sticky Chat Widget",
      "cwe": "CWE-89",
      "title": "WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73187"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-73339",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webnus Inc.",
      "product": "Modern Events Calendar",
      "cwe": "CWE-89",
      "title": "WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73339"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-73355",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Affiliates Manager",
      "cwe": "CWE-89",
      "title": "WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73355"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-73365",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetAppointment",
      "cwe": "CWE-89",
      "title": "WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73365"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-73392",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "highwarden",
      "product": "Super Store Finder",
      "cwe": "CWE-89",
      "title": "WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73392"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-45532",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-22",
      "title": "DataEase has a Path Traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45532"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-54347",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-79",
      "title": "Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54347"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-62607",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customer Care",
      "cwe": null,
      "title": "Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Customer Care. While the vulnerability is in Oracle Customer Care, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customer Care accessible data as well as unauthorized access to critical data or complete access to all Oracle Customer Care accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62607"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-71050",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Lifecycle Analytics",
      "cwe": null,
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71050"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-60865",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": null,
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60865"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-71007",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71007"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-71085",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71085"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-60905",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60905"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-49221",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49221"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-49228",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49228"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-71057",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle BI Publisher",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71057"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-60752",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60752"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-61259",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61259"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-70733",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Profitability and Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70733"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-70933",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70933"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-70934",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70934"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-71880",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GBIF",
      "product": "Integrated Publishing Toolkit",
      "cwe": "CWE-1336",
      "title": "Server-side template injection in Integrated Publishing Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71880"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-70774",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Warehouse Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Warehouse Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Warehouse Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70774"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-62452",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00378,
      "epss_percentile": 0.31095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62452"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-74044",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00378,
      "epss_percentile": 0.31079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wazuh",
      "product": "wazuh-manager",
      "cwe": "CWE-22",
      "title": "Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74044"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-32472",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wbolt.com",
      "product": "Online Contact Widget",
      "cwe": "CWE-862",
      "title": "WordPress Online Contact Widget plugin <= 1.3.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32472"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-32549",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codexpert, Inc",
      "product": "ThumbPress",
      "cwe": "CWE-862",
      "title": "WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32549"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-61029",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00376,
      "epss_percentile": 0.30902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61029"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-70980",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00376,
      "epss_percentile": 0.30905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70980"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-53455",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ha-china",
      "product": "blueprint-studio",
      "cwe": "CWE-78",
      "title": "Blueprint Studio Git credential helper command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53455"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-60415",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60415"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-60742",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60742"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-60831",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60831"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-61307",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CC Common Application Objects",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CC Common Application Objects. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61307"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-62501",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62501"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-62531",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62531"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-70744",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70744"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-70749",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70749"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-70868",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": null,
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70868"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-71035",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71035"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-71053",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71053"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-71068",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71068"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-71112",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Common Objects",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71112"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-52731",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-248",
      "title": "ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52731"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-76042",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00375,
      "epss_percentile": 0.30767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76042"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-54730",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-284",
      "title": "authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54730"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-60861",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": null,
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60861"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-61001",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Web Services Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Services Manager. While the vulnerability is in Oracle Web Services Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Web Services Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61001"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-15585",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.3057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AKIN Software Computer Import Export Industry and Trade Ltd.",
      "product": "AKINSOFT Wolvox9 ERP / KontrolPanel.exe",
      "cwe": "CWE-22",
      "title": "Path Traversal in AKIN Software's Wolvox9 ERP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15585"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-62467",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62467"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-62571",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62571"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-62593",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62593"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-70771",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Warehouse Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Warehouse Management. While the vulnerability is in Oracle Warehouse Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70771"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-70827",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle MES for Process Manufacturing",
      "cwe": null,
      "title": "Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. While the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70827"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-70828",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70828"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-52738",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-248",
      "title": "ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52738"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-62506",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62506"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-70720",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Production Scheduling",
      "cwe": null,
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70720"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-70767",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70767"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-70826",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70826"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-70831",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70831"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-43971",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninenines",
      "product": "cowlib",
      "cwe": "CWE-116",
      "title": "Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43971"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-52732",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-770",
      "title": "ZEBRA: Mempool transaction admission denial via single-peer inbound queue saturation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52732"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-52734",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-401",
      "title": "ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52734"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-75856",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-918",
      "title": "CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75856"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-60841",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60841"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-60849",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60849"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-60765",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60765"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-60956",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne US Payroll",
      "cwe": null,
      "title": "Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD Edwards (component: Payroll). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne US Payroll. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne US Payroll. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60956"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-70713",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSetup",
      "cwe": null,
      "title": "Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in takeover of Oracle iSetup. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70713"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-70829",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Systems",
      "cwe": null,
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70829"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-66620",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Derek Herman",
      "product": "OptionTree",
      "cwe": "CWE-502",
      "title": "WordPress OptionTree plugin <= 2.7.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66620"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-52607",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0037,
      "epss_percentile": 0.3031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52607"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-52610",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0037,
      "epss_percentile": 0.3031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the \"saveTemplate\" parameter in conjuction with \"execute_mode=PREPARE\" parameter in the \"run.php\" endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52610"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-61018",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00365,
      "epss_percentile": 0.29751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61018"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-70846",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00365,
      "epss_percentile": 0.29766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Demand Planning",
      "cwe": null,
      "title": "Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Planning. While the vulnerability is in Oracle Demand Planning, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Planning accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70846"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-61321",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61321"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-62600",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales",
      "cwe": null,
      "title": "Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sales accessible data as well as unauthorized access to critical data or complete access to all Oracle Sales accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62600"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-70671",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70671"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-70708",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales Foundation",
      "cwe": null,
      "title": "Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Suite (component: Security API). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sales Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle Sales Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70708"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-70738",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Profitability and Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70738"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-70805",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Planning and Control",
      "cwe": null,
      "title": "Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Planning and Control. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Planning and Control accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Planning and Control accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70805"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-70929",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70929"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-70957",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70957"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-70999",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70999"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-71110",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71110"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-76041",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00365,
      "epss_percentile": 0.29721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76041"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-63642",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MagicMirrorOrg",
      "product": "MagicMirror",
      "cwe": "CWE-918",
      "title": "MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63642"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-15806",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00363,
      "epss_percentile": 0.29561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-319",
      "title": "`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15806"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-76035",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76035"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-61033",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61033"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-62625",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62625"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-62636",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62636"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-61066",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61066"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-76046",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76046"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-70803",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized read access to a subset of Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70803"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-70880",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70880"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-60971",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.2901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60971"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-61272",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": null,
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61272"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-62539",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62539"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-62541",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62541"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-62543",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62543"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-62585",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.2901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Administration",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Administration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Administration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62585"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-70871",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70871"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-70953",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70953"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-70954",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70954"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-70995",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70995"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-73905",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73905"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-73912",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73912"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-73921",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73921"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-73996",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masteriyo",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-434",
      "title": "WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73996"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-70994",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.2901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70994"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-70997",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70997"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-68922",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MobSF",
      "product": "Mobile-Security-Framework-MobSF",
      "cwe": "CWE-22",
      "title": "MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68922"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-60916",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.28946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized read access to a subset of Oracle WebCenter Enterprise Capture accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60916"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-61574",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-639",
      "title": "authentik RAC: access any endpoint via an unrelated application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61574"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-74904",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.2892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.4 Missing Authorization via block API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74904"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-70849",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.2899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70849"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-73896",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73896"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-21580",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Atlassian",
      "product": "Confluence Data Center",
      "cwe": null,
      "title": "This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Bug Bounty program.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21580"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-60983",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60983"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-70687",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Marketing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70687"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-70723",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Profitability and Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. While the vulnerability is in Oracle Hyperion Profitability and Cost Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70723"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-70942",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70942"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-70988",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70988"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-71056",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71056"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-60830",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Workflow",
      "cwe": null,
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Workflow accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60830"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-70938",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70938"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-70968",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70968"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-71070",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.2878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71070"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-60981",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60981"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-61215",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61215"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-61219",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61219"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-21584",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Atlassian",
      "product": "Bamboo Data Center",
      "cwe": null,
      "title": "This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22 * Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.10 See the release notes (https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html). You can download the latest version of Bamboo Data Center from the download center (https://www.atlassian.com/software/bamboo/download-archives). This vulnerability was reported via our Penetration Testing program.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21584"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-76033",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76033"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-60990",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60990"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-60995",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60995"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-61248",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Internet Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61248"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-70855",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Self Service",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Self Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Self Service accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Self Service accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70855"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-71037",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71037"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-61231",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Virtual Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Virtual Directory. Successful attacks of this vulnerability can result in takeover of Oracle Virtual Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61231"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-62462",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": null,
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62462"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-70812",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Call Center Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70812"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-62591",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62591"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-70746",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70746"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-70901",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70901"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-73383",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebAppick",
      "product": "CTX Feed",
      "cwe": "CWE-22",
      "title": "WordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73383"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-60860",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.2831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": null,
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60860"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-74038",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wazuh",
      "product": "wazuh-manager",
      "cwe": "CWE-22",
      "title": "Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74038"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-74946",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74946"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-74979",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.27944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-284",
      "title": "Mitigation bypass in the Add-ons Manager component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74979"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-71365",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-918",
      "title": "Awx: webhook status callback ssrf leaks the git pat",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71365"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-59825",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-295",
      "title": "Mastodon: Unwanted deactivation of SSL/TLS certificate verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59825"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-47628",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-770",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47628"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-47629",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-20",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47629"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-61212",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61212"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-62590",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62590"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-70718",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Bills of Material",
      "cwe": null,
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70718"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-70859",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70859"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-60679",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60679"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-60769",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": null,
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60769"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-70706",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales",
      "cwe": null,
      "title": "Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in takeover of Oracle Sales. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70706"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-70763",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Operations Intelligence",
      "cwe": null,
      "title": "Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: Daily Business Intelligence). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Operations Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle Operations Intelligence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70763"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-70865",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": null,
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70865"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-70930",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70930"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-70937",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70937"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-70973",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70973"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-71069",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71069"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-71160",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71160"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-73995",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "User Registration",
      "cwe": "CWE-290",
      "title": "WordPress User Registration plugin <= 5.2.6 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73995"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-74941",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Graphics: CanvasWebGL component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74941"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-53454",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.2754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ha-china",
      "product": "blueprint-studio",
      "cwe": "CWE-522",
      "title": "Blueprint Studio stored Git credentials in plaintext Git credential store",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53454"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-71124",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71124"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-75093",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00344,
      "epss_percentile": 0.27588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sonos",
      "product": "tract",
      "cwe": "CWE-120",
      "title": "sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75093"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-32481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ezoic",
      "product": "Ezoic",
      "cwe": "CWE-288",
      "title": "WordPress Ezoic plugin <= 2.22.11 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32481"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-61034",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61034"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-60955",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60955"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-73337",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-287",
      "title": "Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73337"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-62540",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62540"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-70797",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Purchasing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70797"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-70834",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70834"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-71104",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (Netherlands)",
      "cwe": null,
      "title": "Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Netherlands Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Netherlands). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Netherlands). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71104"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-73939",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 8.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73939"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-75842",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-22",
      "title": "ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75842"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-73879",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73879"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-73903",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73903"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-62492",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62492"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-62538",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62538"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-70779",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupplier Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupplier Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70779"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-70783",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Service Contracts",
      "cwe": null,
      "title": "Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70783"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-70823",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70823"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-65985",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-918",
      "title": "FUXA: SSRF hardening for `device-webapi-request`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65985"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-70673",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.26949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70673"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-75837",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.26944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-269",
      "title": "Grav before 2.0.14 Privilege Escalation via Group Access Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75837"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-61038",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.2695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61038"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-61054",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.2695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61054"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-70702",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.2695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payments accessible data as well as unauthorized update, insert or delete access to some of Oracle Payments accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70702"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-70773",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HCM Common Architecture",
      "cwe": null,
      "title": "Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Common Architecture accessible data as well as unauthorized update, insert or delete access to some of Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70773"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-70897",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70897"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-53458",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.26963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ha-china",
      "product": "blueprint-studio",
      "cwe": "CWE-209",
      "title": "Blueprint Studio API exposed internal exception details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53458"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-19501",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00339,
      "epss_percentile": 0.26989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SureForms",
      "product": "SureForms",
      "cwe": null,
      "title": "CVE-2026-19501",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19501"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-53453",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ha-china",
      "product": "blueprint-studio",
      "cwe": "CWE-862",
      "title": "Blueprint Studio API authorization bypass for non-admin Home Assistant users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53453"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-70870",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Client - Unicode). The supported version that is affected is 11.2.23.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70870"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-50143",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apify",
      "product": "apify-mcp-server",
      "cwe": "CWE-918",
      "title": "Actor MCP path authority injection leaks Apify token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50143"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-70725",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Inbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Inbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70725"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-70764",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data as well as unauthorized update, insert or delete access to some of Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70764"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-70856",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70856"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-74977",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "title": "Integer overflow in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74977"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-71573",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-93",
      "title": "Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71573"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-66679",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Appointment Hour Booking",
      "cwe": "CWE-1284",
      "title": "WordPress Appointment Hour Booking plugin <= 1.5.91 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66679"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-71121",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71121"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-61021",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00335,
      "epss_percentile": 0.26556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61021"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-52733",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-459",
      "title": "ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52733"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-50138",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patrickhener",
      "product": "goshs",
      "cwe": "CWE-284",
      "title": "goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50138"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-74949",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Privilege escalation due to use-after-free in the Graphics: Canvas2D component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74949"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-74907",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-22",
      "title": "Grav before 2.0.15 Path Traversal via plugin-asset-map.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74907"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-61124",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61124"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-76044",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76044"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-49226",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49226"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-75082",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00331,
      "epss_percentile": 0.26115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-74",
      "title": "Webkul Bagisto Customer-Registration Notification Email register cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75082"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-75913",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-73",
      "title": "CodeWhale before 0.8.64 Argument Injection via git_show",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75913"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-71017",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71017"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-71059",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.2582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle BI Publisher",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71059"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-50191",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RARgames",
      "product": "4gaBoards",
      "cwe": "CWE-287",
      "title": "4gaBoards: Pre-Account Takeover via SSO Email Linkage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50191"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-61042",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61042"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-61213",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61213"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-61273",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": null,
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61273"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-70707",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.2582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales for Handhelds",
      "cwe": null,
      "title": "Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales for Handhelds. Successful attacks of this vulnerability can result in takeover of Oracle Sales for Handhelds. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70707"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-70787",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70787"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-70792",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Yard Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70792"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-70819",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70819"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-70874",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70874"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-70899",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70899"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-70951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM End User",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Document Management). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in takeover of Siebel CRM End User. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70951"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-70956",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70956"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-70965",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70965"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-71044",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71044"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-71052",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.2582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71052"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-71058",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.2582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle BI Publisher",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71058"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-71150",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71150"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-75778",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System",
      "cwe": "CWE-74",
      "title": "code-projects Task Management System Login Form index.php select_with_multiple_condition sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75778"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-46482",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-636",
      "title": "MyBB: Security Question insufficient validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46482"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-76045",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.2556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76045"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-73189",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "WP Crowdfunding",
      "cwe": "CWE-639",
      "title": "WordPress WP Crowdfunding plugin < 2.2.1 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73189"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-73404",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "MasterStudy LMS",
      "cwe": "CWE-862",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73404"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-70862",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": null,
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Testing Suite accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70862"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-70872",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70872"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-70883",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70883"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-70976",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70976"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-70979",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70979"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-74935",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74935"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-74939",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74939"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-74942",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Remote Settings Client component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74942"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-60748",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": null,
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle General Ledger. While the vulnerability is in Oracle General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data as well as unauthorized update, insert or delete access to some of Oracle General Ledger accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60748"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-73882",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73882"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-73890",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73890"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-73902",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73902"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-73915",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73915"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-73934",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73934"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-73935",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73935"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-71167",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00323,
      "epss_percentile": 0.25254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71167"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-73920",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00323,
      "epss_percentile": 0.25254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73920"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-70778",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Customer Care",
      "cwe": null,
      "title": "Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Care, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customer Care accessible data as well as unauthorized access to critical data or complete access to all Oracle Customer Care accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70778"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-70882",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70882"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-70903",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70903"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-71000",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71000"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-71024",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71024"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-61208",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61208"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-71048",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Lifecycle Analytics",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71048"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-73377",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Ultimate Maps by Supsystic",
      "cwe": "CWE-862",
      "title": "WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73377"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-73994",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "Charitable",
      "cwe": "CWE-862",
      "title": "WordPress Charitable plugin <= 1.8.11.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73994"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-75836",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.2507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav API Plugin before 1.0.14 Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75836"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-75912",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-88",
      "title": "CodeWhale before 0.8.64 Argument Injection via git_blame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75912"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-62631",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62631"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-53959",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.24959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RARgames",
      "product": "4gaBoards",
      "cwe": "CWE-200",
      "title": "4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53959"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-71572",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.2501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-93",
      "title": "Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71572"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-73426",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.24949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "basecamp",
      "product": "trix",
      "cwe": "CWE-79",
      "title": "Trix: Stored XSS vulnerability through serialized attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73426"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-60944",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60944"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-61222",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61222"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-62485",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62485"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-61288",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61288"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-72531",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72531"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-72532",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72532"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-60903",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60903"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-60934",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60934"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-60935",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60935"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-60954",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60954"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-60980",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60980"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-73929",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73929"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-60759",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Internet Procurement Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60759"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-60766",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60766"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-60792",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60792"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-60797",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60797"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-60803",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Marketing accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60803"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-60820",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-1284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60820"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-60856",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Install and Packaging). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60856"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-60915",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60915"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-60933",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60933"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-70672",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70672"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-71009",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71009"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-71143",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Communications Unified Inventory Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Third Party). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0-7.8.0 and 8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71143"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-70837",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials for Asia/Pacific",
      "cwe": null,
      "title": "Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for Asia/Pacific. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials for Asia/Pacific accessible data as well as unauthorized read access to a subset of Oracle Financials for Asia/Pacific accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70837"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-61308",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition",
      "cwe": null,
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61308"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-70982",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70982"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-70983",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70983"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-70990",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70990"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-73395",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevart",
      "product": "Booking calendar, Appointment Booking System",
      "cwe": "CWE-639",
      "title": "WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73395"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-47721",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-862",
      "title": "FUXA: Scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47721"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-63337",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.2451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-470",
      "title": "RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63337"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-74905",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.2452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-918",
      "title": "SiYuan before v3.7.4 SSRF via IPv6 Transition Address Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74905"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-70657",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "9001",
      "product": "copyparty",
      "cwe": "CWE-863",
      "title": "Copyparty: file/dirkey confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70657"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-75851",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-269",
      "title": "ArcadeDB before 26.8.1 Authentication Bypass via Async Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75851"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-74953",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Networking: Cookies component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74953"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-61230",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61230"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-62596",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62596"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-70807",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Call Center Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. While the vulnerability is in Oracle Call Center Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Call Center Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Call Center Technology accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70807"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-62552",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62552"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-70777",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupplier Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70777"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-70890",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70890"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-60781",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payments accessible data as well as unauthorized update, insert or delete access to some of Oracle Payments accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60781"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-62587",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Administration",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Administration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Administration accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62587"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-70816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials for EMEA",
      "cwe": null,
      "title": "Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for EMEA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials for EMEA accessible data as well as unauthorized update, insert or delete access to some of Oracle Financials for EMEA accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70816"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-70833",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Landed Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70833"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-70839",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials for EMEA",
      "cwe": null,
      "title": "Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for EMEA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials for EMEA accessible data as well as unauthorized update, insert or delete access to some of Oracle Financials for EMEA accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70839"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-74046",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wazuh",
      "product": "wazuh-manager",
      "cwe": "CWE-409",
      "title": "Wazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip Bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74046"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-62509",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62509"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-62510",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62510"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-62566",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62566"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-62579",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62579"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-70727",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70727"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-70754",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70754"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-70911",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70911"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-71076",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71076"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-71100",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized read access to a subset of RDBMS accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71100"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-71148",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71148"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-71157",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71157"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-73877",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73877"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-73888",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73888"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-73889",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73889"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-73895",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73895"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-73899",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73899"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-73906",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73906"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-73336",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73336"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-74938",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00315,
      "epss_percentile": 0.24345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the JavaScript: GC component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74938"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-28191",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.2436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Theme-One Inc.",
      "product": "The Grid",
      "cwe": "CWE-266",
      "title": "WordPress The Grid plugin <= 2.7.9.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28191"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-61293",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61293"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-75840",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-1025",
      "title": "ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75840"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-50577",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fbeta-GmbH",
      "product": "ePA3-Service-OpenSource",
      "cwe": "CWE-323",
      "title": "ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50577"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-71120",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71120"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-18504",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify",
      "product": "fastify",
      "cwe": "CWE-20",
      "title": "fastify vulnerable to schema validation bypass via root primitive coercion mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18504"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-65959",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vitessio",
      "product": "vitess",
      "cwe": "CWE-862",
      "title": "Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65959"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-18534",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Browser Company of New York",
      "product": "ArcSearch",
      "cwe": "CWE-1021",
      "title": "Address bar spoofing risk in affected iOS versions of Arc Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18534"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-70724",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Cluster",
      "cwe": null,
      "title": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.0-8.0.48, 8.4.0-8.4.11 and 9.7.0-9.7.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70724"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-61290",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61290"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-15571",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.2362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.6",
      "cwe": "CWE-341",
      "title": "Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15571"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-73373",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-434",
      "title": "Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73373"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-19671",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISAgov",
      "product": "Malcolm",
      "cwe": "CWE-409",
      "title": "Improper handling of highly compressed data (data amplification) in CISA Malcolm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19671"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-61306",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Complex Maintenance, Repair and Overhaul",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61306"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-52877",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-20",
      "title": "Streambert : Insecure Protocol Execution in open-external IPC Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52877"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-67442",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00305,
      "epss_percentile": 0.23225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frangoteam",
      "product": "FUXA",
      "cwe": "CWE-284",
      "title": "FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67442"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-45733",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-79",
      "title": "Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45733"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-70694",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in Oracle Payments, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70694"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-70695",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in Oracle Payments, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70695"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-73894",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73894"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-73918",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73918"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-71060",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71060"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-75843",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-269",
      "title": "ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75843"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-62610",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62610"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-70668",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70668"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-71014",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71014"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-71036",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71036"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-73865",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73865"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-73922",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73922"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-73924",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73924"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-61228",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61228"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-62535",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62535"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-62620",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62620"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-70996",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70996"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-60758",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Artificial Intelligence",
      "cwe": null,
      "title": "Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Artificial Intelligence. While the vulnerability is in Siebel Artificial Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Artificial Intelligence accessible data as well as unauthorized update, insert or delete access to some of Siebel Artificial Intelligence accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60758"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-60798",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60798"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-61326",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61326"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-70728",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Autonomous Health Framework",
      "cwe": null,
      "title": "Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Autonomous Health Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Autonomous Health Framework accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70728"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-71049",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Lifecycle Analytics",
      "cwe": null,
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71049"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-32468",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rayhanduitku",
      "product": "Duitku Payment Gateway",
      "cwe": "CWE-497",
      "title": "WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32468"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-70696",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70696"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-70947",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Purchasing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70947"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-70985",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70985"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-71038",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71038"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-71043",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71043"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-71061",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71061"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-73887",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73887"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-73908",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73908"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-62601",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Sales",
      "cwe": null,
      "title": "Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales accessible data as well as unauthorized update, insert or delete access to some of Oracle Sales accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62601"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-70736",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Profitability and Cost Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70736"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-70808",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scripting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Scripting accessible data as well as unauthorized update, insert or delete access to some of Oracle Scripting accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70808"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-70844",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Loans",
      "cwe": null,
      "title": "Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Loans accessible data as well as unauthorized update, insert or delete access to some of Oracle Loans accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70844"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-70971",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70971"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-45116",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-79",
      "title": "MyBB: Profile field type confusion XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45116"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-55839",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-79",
      "title": "Kestra: Stored XSS via custom Markdown [[link]] attribute injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55839"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-52793",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-287",
      "title": "Froxlor: API Authentication bypasses 2FA Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52793"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-70790",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Telecommunications Billing Integrator",
      "cwe": null,
      "title": "Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Telecommunications Billing Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Telecommunications Billing Integrator accessible data. CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70790"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2026-60693",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60693"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2026-70809",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Scripting",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scripting. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70809"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2026-50576",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fbeta-GmbH",
      "product": "ePA3-Service-OpenSource",
      "cwe": "CWE-113",
      "title": "ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50576"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-45125",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.2283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-93",
      "title": "MyBB: Email User CRLF injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45125"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-61340",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle MES for Process Manufacturing",
      "cwe": null,
      "title": "Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61340"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-71018",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71018"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-11801",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gwin",
      "product": "WPAdverts – Classifieds Plugin",
      "cwe": "CWE-862",
      "title": "WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via classifieds-types REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11801"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-75838",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75838"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-61634",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00299,
      "epss_percentile": 0.22575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-20",
      "title": "RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61634"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-62582",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62582"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-74906",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-863",
      "title": "SiYuan before v3.7.4 Incorrect Authorization via Publish Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74906"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-61268",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": null,
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61268"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-61270",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Orchestrator",
      "cwe": null,
      "title": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Orchestrator accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61270"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-70782",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Labor Distribution",
      "cwe": null,
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Labor Distribution accessible data as well as unauthorized access to critical data or complete access to all Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70782"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-70830",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Systems",
      "cwe": null,
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70830"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-49222",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49222"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-49223",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.2246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete reviews under other Vendors' products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49223"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-49227",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-639",
      "title": "Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49227"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-73529",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alextselegidis",
      "product": "plainpad",
      "cwe": "CWE-307",
      "title": "Plainpad Missing Rate Limiting via POST /v1/sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73529"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-41921",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koha Community",
      "product": "Koha",
      "cwe": "CWE-79",
      "title": "Koha Stored XSS via Purchase Suggestion Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41921"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-23938",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00298,
      "epss_percentile": 0.22455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-248",
      "title": "Server DoS via JavaScript preprocessing or script items",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23938"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-74965",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Shell Integration component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74965"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-75898",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infiniflow",
      "product": "ragflow",
      "cwe": "CWE-918",
      "title": "RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75898"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-61305",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle BI Publisher",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61305"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-70679",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70679"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-23929",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-1321",
      "title": "Prototype pollution leading to stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23929"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-71002",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71002"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-74039",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.2212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wazuh",
      "product": "wazuh-manager",
      "cwe": "CWE-770",
      "title": "Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74039"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-69160",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenListTeam",
      "product": "OpenList",
      "cwe": "CWE-639",
      "title": "OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69160"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-73398",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Papaki (Enartia S.A.)",
      "product": "Piraeus Bank WooCommerce Payment Gateway",
      "cwe": "CWE-288",
      "title": "WordPress Piraeus Bank WooCommerce Payment Gateway plugin 3.2.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73398"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-62460",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62460"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-61229",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61229"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-62471",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62471"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-70795",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Platform Engineering",
      "cwe": null,
      "title": "Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (component: Valid Session). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Applications Platform Engineering. Successful attacks of this vulnerability can result in takeover of Oracle Applications Platform Engineering. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70795"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-73371",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73371"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-73372",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73372"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-63335",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-20",
      "title": "RabbitMQ Java client malformed body frame triggers raw command assembler exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63335"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-48796",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cefsharp",
      "product": "CefSharp",
      "cwe": "CWE-22",
      "title": "CefSharp: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48796"
    },
    {
      "rank": 778,
      "cve_id": "CVE-2026-70907",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70907"
    },
    {
      "rank": 779,
      "cve_id": "CVE-2026-73932",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73932"
    },
    {
      "rank": 780,
      "cve_id": "CVE-2026-74937",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the JavaScript: GC component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74937"
    },
    {
      "rank": 781,
      "cve_id": "CVE-2026-45115",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-79",
      "title": "MyBB: Buddy/ignore list username XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45115"
    },
    {
      "rank": 782,
      "cve_id": "CVE-2026-62598",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SFTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62598"
    },
    {
      "rank": 783,
      "cve_id": "CVE-2026-70703",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70703"
    },
    {
      "rank": 784,
      "cve_id": "CVE-2026-70893",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70893"
    },
    {
      "rank": 785,
      "cve_id": "CVE-2026-70964",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70964"
    },
    {
      "rank": 786,
      "cve_id": "CVE-2026-60895",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60895"
    },
    {
      "rank": 787,
      "cve_id": "CVE-2026-70972",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70972"
    },
    {
      "rank": 788,
      "cve_id": "CVE-2026-52735",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-684",
      "title": "ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52735"
    },
    {
      "rank": 789,
      "cve_id": "CVE-2026-74015",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "merkulove",
      "product": "Readabler",
      "cwe": "CWE-89",
      "title": "WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74015"
    },
    {
      "rank": 790,
      "cve_id": "CVE-2026-61286",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61286"
    },
    {
      "rank": 791,
      "cve_id": "CVE-2026-47699",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "confidential-containers",
      "product": "guest-components",
      "cwe": "CWE-22",
      "title": "Confidential Containers Guest Components image-rs: zip-slip-class arbitrary file write via absolute entry path in hardlink fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47699"
    },
    {
      "rank": 792,
      "cve_id": "CVE-2026-60996",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Connectors and Connector Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60996"
    },
    {
      "rank": 793,
      "cve_id": "CVE-2026-75829",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-1336",
      "title": "grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75829"
    },
    {
      "rank": 794,
      "cve_id": "CVE-2026-69189",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hoppscotch",
      "product": "hoppscotch",
      "cwe": "CWE-200",
      "title": "Hoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolvers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69189"
    },
    {
      "rank": 795,
      "cve_id": "CVE-2026-62481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62481"
    },
    {
      "rank": 796,
      "cve_id": "CVE-2026-70935",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.2146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70935"
    },
    {
      "rank": 797,
      "cve_id": "CVE-2026-71003",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71003"
    },
    {
      "rank": 798,
      "cve_id": "CVE-2026-71012",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.2146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71012"
    },
    {
      "rank": 799,
      "cve_id": "CVE-2026-71008",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71008"
    },
    {
      "rank": 800,
      "cve_id": "CVE-2026-62555",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62555"
    },
    {
      "rank": 801,
      "cve_id": "CVE-2026-71091",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71091"
    },
    {
      "rank": 802,
      "cve_id": "CVE-2026-67920",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00289,
      "epss_percentile": 0.21454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67920"
    },
    {
      "rank": 803,
      "cve_id": "CVE-2026-32465",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "g5theme",
      "product": "Essential Real Estate",
      "cwe": "CWE-502",
      "title": "WordPress Essential Real Estate plugin <= 5.3.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32465"
    },
    {
      "rank": 804,
      "cve_id": "CVE-2026-60967",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.2136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60967"
    },
    {
      "rank": 805,
      "cve_id": "CVE-2026-71045",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71045"
    },
    {
      "rank": 806,
      "cve_id": "CVE-2026-28567",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.2124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fahad Mahmood",
      "product": "WP Sort Order",
      "cwe": "CWE-862",
      "title": "WordPress WP Sort Order plugin <= 1.3.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28567"
    },
    {
      "rank": 807,
      "cve_id": "CVE-2026-28571",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPPOOL",
      "product": "FormyChat",
      "cwe": "CWE-862",
      "title": "WordPress FormyChat plugin <= 2.15.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28571"
    },
    {
      "rank": 808,
      "cve_id": "CVE-2026-60909",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60909"
    },
    {
      "rank": 809,
      "cve_id": "CVE-2026-61227",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61227"
    },
    {
      "rank": 810,
      "cve_id": "CVE-2026-70974",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70974"
    },
    {
      "rank": 811,
      "cve_id": "CVE-2026-60733",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized read access to a subset of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60733"
    },
    {
      "rank": 812,
      "cve_id": "CVE-2026-70769",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70769"
    },
    {
      "rank": 813,
      "cve_id": "CVE-2026-74956",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00282,
      "epss_percentile": 0.20813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-843",
      "title": "Same-origin policy bypass in the DOM: Service Workers component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74956"
    },
    {
      "rank": 814,
      "cve_id": "CVE-2026-70993",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70993"
    },
    {
      "rank": 815,
      "cve_id": "CVE-2026-28570",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpabRice",
      "product": "Vavo Core",
      "cwe": "CWE-98",
      "title": "WordPress Vavo Core plugin <= 2.3.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28570"
    },
    {
      "rank": 816,
      "cve_id": "CVE-2026-32464",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vladimir Prelovac",
      "product": "Theme Test Drive",
      "cwe": "CWE-98",
      "title": "WordPress Theme Test Drive plugin <= 2.9.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32464"
    },
    {
      "rank": 817,
      "cve_id": "CVE-2026-70692",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Marketing Encyclopedia System",
      "cwe": null,
      "title": "Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing Encyclopedia System. While the vulnerability is in Oracle Marketing Encyclopedia System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing Encyclopedia System accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70692"
    },
    {
      "rank": 818,
      "cve_id": "CVE-2026-70676",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70676"
    },
    {
      "rank": 819,
      "cve_id": "CVE-2026-70824",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70824"
    },
    {
      "rank": 820,
      "cve_id": "CVE-2026-70825",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70825"
    },
    {
      "rank": 821,
      "cve_id": "CVE-2026-74009",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Razorpay",
      "product": "Razorpay for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Razorpay for WooCommerce plugin <= 4.8.7 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74009"
    },
    {
      "rank": 822,
      "cve_id": "CVE-2026-23922",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-522",
      "title": "Email media OAuth secret leak to Super Admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23922"
    },
    {
      "rank": 823,
      "cve_id": "CVE-2026-62442",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62442"
    },
    {
      "rank": 824,
      "cve_id": "CVE-2026-62595",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Integration executes to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62595"
    },
    {
      "rank": 825,
      "cve_id": "CVE-2026-70904",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70904"
    },
    {
      "rank": 826,
      "cve_id": "CVE-2026-60998",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60998"
    },
    {
      "rank": 827,
      "cve_id": "CVE-2026-71122",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71122"
    },
    {
      "rank": 828,
      "cve_id": "CVE-2026-62594",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62594"
    },
    {
      "rank": 829,
      "cve_id": "CVE-2026-70751",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70751"
    },
    {
      "rank": 830,
      "cve_id": "CVE-2026-70888",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70888"
    },
    {
      "rank": 831,
      "cve_id": "CVE-2026-70788",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70788"
    },
    {
      "rank": 832,
      "cve_id": "CVE-2026-70716",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70716"
    },
    {
      "rank": 833,
      "cve_id": "CVE-2026-19869",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neo4j",
      "product": "graphql",
      "cwe": "CWE-639",
      "title": "Privilege Escalation via Dropped Field-Level @authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19869"
    },
    {
      "rank": 834,
      "cve_id": "CVE-2026-75830",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-73",
      "title": "grav-plugin-api before 1.0.15 Path Traversal via batchCopy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75830"
    },
    {
      "rank": 835,
      "cve_id": "CVE-2026-63641",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00279,
      "epss_percentile": 0.20458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MagicMirrorOrg",
      "product": "MagicMirror",
      "cwe": "CWE-284",
      "title": "MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63641"
    },
    {
      "rank": 836,
      "cve_id": "CVE-2026-32466",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPExperts",
      "product": "Gravity Forms Bookings premium",
      "cwe": "CWE-89",
      "title": "WordPress Gravity Forms Bookings premium plugin <= 2.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32466"
    },
    {
      "rank": 837,
      "cve_id": "CVE-2026-61177",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61177"
    },
    {
      "rank": 838,
      "cve_id": "CVE-2026-53958",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RARgames",
      "product": "4gaBoards",
      "cwe": "CWE-287",
      "title": "4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53958"
    },
    {
      "rank": 839,
      "cve_id": "CVE-2026-52873",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-79",
      "title": "Streambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electron Renderer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52873"
    },
    {
      "rank": 840,
      "cve_id": "CVE-2026-48744",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saleor",
      "product": "saleor",
      "cwe": "CWE-285",
      "title": "Saleor: Anonymous users can modify channel settings via `channelUpdate` due to `all([])` bypass in permission check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48744"
    },
    {
      "rank": 841,
      "cve_id": "CVE-2026-23937",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-203",
      "title": "Host PSK extraction in Zabbix API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23937"
    },
    {
      "rank": 842,
      "cve_id": "CVE-2026-23931",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-203",
      "title": "Frontend plaintext macro value enumeration via the validatate.api.exists action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23931"
    },
    {
      "rank": 843,
      "cve_id": "CVE-2026-74971",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the DOM: UI Events & Focus Handling component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74971"
    },
    {
      "rank": 844,
      "cve_id": "CVE-2026-74972",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the DOM: Push Subscriptions component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74972"
    },
    {
      "rank": 845,
      "cve_id": "CVE-2026-76032",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydio",
      "product": "cells",
      "cwe": "CWE-862",
      "title": "Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76032"
    },
    {
      "rank": 846,
      "cve_id": "CVE-2026-75130",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uptash",
      "product": "Context7",
      "cwe": "CWE-1427",
      "title": "Context7 2.1.2 Prompt Injection via Custom AI Instructions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75130"
    },
    {
      "rank": 847,
      "cve_id": "CVE-2026-62589",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.20011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62589"
    },
    {
      "rank": 848,
      "cve_id": "CVE-2026-61045",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.20006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61045"
    },
    {
      "rank": 849,
      "cve_id": "CVE-2026-73345",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "License Manager for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress License Manager for WooCommerce plugin <= 3.0.18 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73345"
    },
    {
      "rank": 850,
      "cve_id": "CVE-2026-70851",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00274,
      "epss_percentile": 0.19861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70851"
    },
    {
      "rank": 851,
      "cve_id": "CVE-2026-49452",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kozea",
      "product": "WeasyPrint",
      "cwe": "CWE-74",
      "title": "WeasyPrint: CSS Injection via Presentational Hints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49452"
    },
    {
      "rank": 852,
      "cve_id": "CVE-2026-62623",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62623"
    },
    {
      "rank": 853,
      "cve_id": "CVE-2026-70715",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Autonomous Health Framework",
      "cwe": null,
      "title": "Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70715"
    },
    {
      "rank": 854,
      "cve_id": "CVE-2026-24184",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Cumulus Linux GA",
      "cwe": "CWE-120",
      "title": "NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24184"
    },
    {
      "rank": 855,
      "cve_id": "CVE-2026-70775",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Installed Base",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70775"
    },
    {
      "rank": 856,
      "cve_id": "CVE-2026-71103",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71103"
    },
    {
      "rank": 857,
      "cve_id": "CVE-2026-75841",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-770",
      "title": "ArcadeDB before 26.8.1 Denial of Service via range()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75841"
    },
    {
      "rank": 858,
      "cve_id": "CVE-2026-75828",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00271,
      "epss_percentile": 0.19411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75828"
    },
    {
      "rank": 859,
      "cve_id": "CVE-2026-71162",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71162"
    },
    {
      "rank": 860,
      "cve_id": "CVE-2026-73914",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73914"
    },
    {
      "rank": 861,
      "cve_id": "CVE-2026-62615",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62615"
    },
    {
      "rank": 862,
      "cve_id": "CVE-2026-70885",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70885"
    },
    {
      "rank": 863,
      "cve_id": "CVE-2026-71062",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71062"
    },
    {
      "rank": 864,
      "cve_id": "CVE-2026-60969",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": null,
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60969"
    },
    {
      "rank": 865,
      "cve_id": "CVE-2026-61199",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61199"
    },
    {
      "rank": 866,
      "cve_id": "CVE-2026-61331",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials Common Modules",
      "cwe": null,
      "title": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. While the vulnerability is in Oracle Financials Common Modules, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61331"
    },
    {
      "rank": 867,
      "cve_id": "CVE-2026-70945",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70945"
    },
    {
      "rank": 868,
      "cve_id": "CVE-2026-70875",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70875"
    },
    {
      "rank": 869,
      "cve_id": "CVE-2026-70946",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70946"
    },
    {
      "rank": 870,
      "cve_id": "CVE-2025-9211",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Otalio",
      "product": "Ship Property Management System",
      "cwe": "CWE-79",
      "title": "Cross-site scripting in Otalio Ship Property Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9211"
    },
    {
      "rank": 871,
      "cve_id": "CVE-2026-70732",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Mobile Application Server",
      "cwe": null,
      "title": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70732"
    },
    {
      "rank": 872,
      "cve_id": "CVE-2026-70969",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70969"
    },
    {
      "rank": 873,
      "cve_id": "CVE-2026-70975",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70975"
    },
    {
      "rank": 874,
      "cve_id": "CVE-2026-71001",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71001"
    },
    {
      "rank": 875,
      "cve_id": "CVE-2026-52608",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0027,
      "epss_percentile": 0.19274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52608"
    },
    {
      "rank": 876,
      "cve_id": "CVE-2026-70887",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70887"
    },
    {
      "rank": 877,
      "cve_id": "CVE-2026-71032",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71032"
    },
    {
      "rank": 878,
      "cve_id": "CVE-2026-73875",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73875"
    },
    {
      "rank": 879,
      "cve_id": "CVE-2026-73876",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73876"
    },
    {
      "rank": 880,
      "cve_id": "CVE-2026-73885",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73885"
    },
    {
      "rank": 881,
      "cve_id": "CVE-2026-73886",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73886"
    },
    {
      "rank": 882,
      "cve_id": "CVE-2026-73928",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73928"
    },
    {
      "rank": 883,
      "cve_id": "CVE-2026-70845",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Loans",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Loans. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70845"
    },
    {
      "rank": 884,
      "cve_id": "CVE-2026-60682",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60682"
    },
    {
      "rank": 885,
      "cve_id": "CVE-2026-60866",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Service Delivery Platform",
      "cwe": null,
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Service Delivery Platform accessible data as well as unauthorized read access to a subset of Service Delivery Platform accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60866"
    },
    {
      "rank": 886,
      "cve_id": "CVE-2026-61198",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Learning Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Learning Management accessible data as well as unauthorized read access to a subset of Oracle Learning Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61198"
    },
    {
      "rank": 887,
      "cve_id": "CVE-2026-73867",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73867"
    },
    {
      "rank": 888,
      "cve_id": "CVE-2026-73868",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73868"
    },
    {
      "rank": 889,
      "cve_id": "CVE-2026-73893",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73893"
    },
    {
      "rank": 890,
      "cve_id": "CVE-2026-73897",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73897"
    },
    {
      "rank": 891,
      "cve_id": "CVE-2026-45123",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-918",
      "title": "MyBB: IPv6 SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45123"
    },
    {
      "rank": 892,
      "cve_id": "CVE-2026-47245",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-252",
      "title": "MyBB: Buddy list corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47245"
    },
    {
      "rank": 893,
      "cve_id": "CVE-2026-60853",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00269,
      "epss_percentile": 0.19191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60853"
    },
    {
      "rank": 894,
      "cve_id": "CVE-2026-61281",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61281"
    },
    {
      "rank": 895,
      "cve_id": "CVE-2026-70786",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Service Fulfillment Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70786"
    },
    {
      "rank": 896,
      "cve_id": "CVE-2026-70864",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.1903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": null,
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70864"
    },
    {
      "rank": 897,
      "cve_id": "CVE-2026-70960",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70960"
    },
    {
      "rank": 898,
      "cve_id": "CVE-2026-71027",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71027"
    },
    {
      "rank": 899,
      "cve_id": "CVE-2026-62523",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62523"
    },
    {
      "rank": 900,
      "cve_id": "CVE-2026-70753",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70753"
    },
    {
      "rank": 901,
      "cve_id": "CVE-2026-75858",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-94",
      "title": "CodeWhale rlm_eval before 0.8.64 Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75858"
    },
    {
      "rank": 902,
      "cve_id": "CVE-2026-62616",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.1892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 7.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62616"
    },
    {
      "rank": 903,
      "cve_id": "CVE-2026-62526",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00267,
      "epss_percentile": 0.18987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.3 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62526"
    },
    {
      "rank": 904,
      "cve_id": "CVE-2026-32463",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00266,
      "epss_percentile": 0.18886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kamlesh Parmar",
      "product": "Sync Post With Other Site",
      "cwe": "CWE-434",
      "title": "WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32463"
    },
    {
      "rank": 905,
      "cve_id": "CVE-2026-70804",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Human Resources",
      "cwe": null,
      "title": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70804"
    },
    {
      "rank": 906,
      "cve_id": "CVE-2026-74958",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-1021",
      "title": "Information disclosure in the WebRTC component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74958"
    },
    {
      "rank": 907,
      "cve_id": "CVE-2026-62458",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": null,
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Work in Process as well as unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62458"
    },
    {
      "rank": 908,
      "cve_id": "CVE-2026-75089",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Complaint Management System",
      "cwe": "CWE-74",
      "title": "PHPGurukul Complaint Management System check_availability.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75089"
    },
    {
      "rank": 909,
      "cve_id": "CVE-2026-70683",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70683"
    },
    {
      "rank": 910,
      "cve_id": "CVE-2026-70791",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Transportation Execution",
      "cwe": null,
      "title": "Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70791"
    },
    {
      "rank": 911,
      "cve_id": "CVE-2026-68927",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MobSF",
      "product": "Mobile-Security-Framework-MobSF",
      "cwe": "CWE-918",
      "title": "MobSF: SSRF port restriction bypass in assetlinks_check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68927"
    },
    {
      "rank": 912,
      "cve_id": "CVE-2026-73356",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloudways",
      "product": "Breeze",
      "cwe": "CWE-862",
      "title": "WordPress Breeze plugin <= 2.5.12 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73356"
    },
    {
      "rank": 913,
      "cve_id": "CVE-2026-30250",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30250"
    },
    {
      "rank": 914,
      "cve_id": "CVE-2026-75626",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smicallef",
      "product": "spiderfoot",
      "cwe": "CWE-79",
      "title": "SpiderFoot Stored Cross-Site Scripting via Correlation Titles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75626"
    },
    {
      "rank": 915,
      "cve_id": "CVE-2026-12564",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00259,
      "epss_percentile": 0.17739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-918",
      "title": "Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12564"
    },
    {
      "rank": 916,
      "cve_id": "CVE-2026-71574",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71574"
    },
    {
      "rank": 917,
      "cve_id": "CVE-2026-71023",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.1779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71023"
    },
    {
      "rank": 918,
      "cve_id": "CVE-2026-66634",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pantherius",
      "product": "Modal Survey",
      "cwe": "CWE-639",
      "title": "WordPress Modal Survey plugin <= 2.0.2.2.3 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66634"
    },
    {
      "rank": 919,
      "cve_id": "CVE-2026-62618",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62618"
    },
    {
      "rank": 920,
      "cve_id": "CVE-2026-70998",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70998"
    },
    {
      "rank": 921,
      "cve_id": "CVE-2026-71065",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71065"
    },
    {
      "rank": 922,
      "cve_id": "CVE-2026-70852",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Demand Planning",
      "cwe": null,
      "title": "Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data as well as unauthorized update, insert or delete access to some of Oracle Demand Planning accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70852"
    },
    {
      "rank": 923,
      "cve_id": "CVE-2026-71130",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71130"
    },
    {
      "rank": 924,
      "cve_id": "CVE-2026-71159",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.1764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71159"
    },
    {
      "rank": 925,
      "cve_id": "CVE-2026-70857",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM End User",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70857"
    },
    {
      "rank": 926,
      "cve_id": "CVE-2026-60589",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition",
      "cwe": null,
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60589"
    },
    {
      "rank": 927,
      "cve_id": "CVE-2026-62533",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62533"
    },
    {
      "rank": 928,
      "cve_id": "CVE-2026-70848",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70848"
    },
    {
      "rank": 929,
      "cve_id": "CVE-2026-70670",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70670"
    },
    {
      "rank": 930,
      "cve_id": "CVE-2026-71063",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71063"
    },
    {
      "rank": 931,
      "cve_id": "CVE-2026-71064",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": null,
      "title": "Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71064"
    },
    {
      "rank": 932,
      "cve_id": "CVE-2026-61193",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61193"
    },
    {
      "rank": 933,
      "cve_id": "CVE-2026-70900",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70900"
    },
    {
      "rank": 934,
      "cve_id": "CVE-2026-70699",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.1752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70699"
    },
    {
      "rank": 935,
      "cve_id": "CVE-2026-70898",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70898"
    },
    {
      "rank": 936,
      "cve_id": "CVE-2026-71029",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71029"
    },
    {
      "rank": 937,
      "cve_id": "CVE-2026-73909",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.1752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73909"
    },
    {
      "rank": 938,
      "cve_id": "CVE-2026-62532",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00257,
      "epss_percentile": 0.17605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62532"
    },
    {
      "rank": 939,
      "cve_id": "CVE-2026-74954",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-203",
      "title": "Information disclosure due to side-channel in the Storage: Cache API component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74954"
    },
    {
      "rank": 940,
      "cve_id": "CVE-2026-32473",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DeKnows",
      "product": "PDF Smart Viewer for Elementor",
      "cwe": "CWE-918",
      "title": "WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32473"
    },
    {
      "rank": 941,
      "cve_id": "CVE-2026-32553",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "OttoKit",
      "cwe": "CWE-918",
      "title": "WordPress OttoKit plugin <= 1.1.35 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32553"
    },
    {
      "rank": 942,
      "cve_id": "CVE-2026-73352",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-862",
      "title": "WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73352"
    },
    {
      "rank": 943,
      "cve_id": "CVE-2026-70892",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70892"
    },
    {
      "rank": 944,
      "cve_id": "CVE-2026-62499",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62499"
    },
    {
      "rank": 945,
      "cve_id": "CVE-2026-55106",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.1689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-862",
      "title": "authentik: Unauthenticated LDAP directory data disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55106"
    },
    {
      "rank": 946,
      "cve_id": "CVE-2026-75831",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav before 2.0.15 Stored XSS via audio/video source URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75831"
    },
    {
      "rank": 947,
      "cve_id": "CVE-2026-62441",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62441"
    },
    {
      "rank": 948,
      "cve_id": "CVE-2026-62446",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62446"
    },
    {
      "rank": 949,
      "cve_id": "CVE-2026-71088",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71088"
    },
    {
      "rank": 950,
      "cve_id": "CVE-2026-45121",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.1676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-863",
      "title": "MyBB: Insufficient permission check for calendar select",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45121"
    },
    {
      "rank": 951,
      "cve_id": "CVE-2026-70867",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": null,
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70867"
    },
    {
      "rank": 952,
      "cve_id": "CVE-2026-19608",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-285",
      "title": "Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy path-specific group policies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19608"
    },
    {
      "rank": 953,
      "cve_id": "CVE-2026-75876",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xianrendzw",
      "product": "EasyReport",
      "cwe": "CWE-74",
      "title": "xianrendzw EasyReport Move Operations ModuleController.java sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75876"
    },
    {
      "rank": 954,
      "cve_id": "CVE-2026-75846",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-862",
      "title": "ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTION",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75846"
    },
    {
      "rank": 955,
      "cve_id": "CVE-2026-68568",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "MasterStudy LMS",
      "cwe": "CWE-266",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68568"
    },
    {
      "rank": 956,
      "cve_id": "CVE-2026-73367",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Easy Google Maps",
      "cwe": "CWE-829",
      "title": "WordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73367"
    },
    {
      "rank": 957,
      "cve_id": "CVE-2026-12632",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Zephyr PTP message parsing from unvalidated message type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12632"
    },
    {
      "rank": 958,
      "cve_id": "CVE-2026-74978",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-1021",
      "title": "Clickjacking issue in the Widget component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74978"
    },
    {
      "rank": 959,
      "cve_id": "CVE-2026-66622",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "averta",
      "product": "Depicter Slider",
      "cwe": "CWE-89",
      "title": "WordPress Depicter Slider plugin <= 4.8.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66622"
    },
    {
      "rank": 960,
      "cve_id": "CVE-2026-54570",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AngleSharp",
      "product": "AngleSharp",
      "cwe": "CWE-80",
      "title": "AngleSharp: HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54570"
    },
    {
      "rank": 961,
      "cve_id": "CVE-2026-50139",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patrickhener",
      "product": "goshs",
      "cwe": "CWE-362",
      "title": "goshs: Share-link ?token=… redemption races past download limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50139"
    },
    {
      "rank": 962,
      "cve_id": "CVE-2026-45122",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-863",
      "title": "MyBB: Insufficient permission check for calendar event move",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45122"
    },
    {
      "rank": 963,
      "cve_id": "CVE-2026-45124",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-862",
      "title": "MyBB: Mod CP report resolution missing authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45124"
    },
    {
      "rank": 964,
      "cve_id": "CVE-2026-71090",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71090"
    },
    {
      "rank": 965,
      "cve_id": "CVE-2024-14045",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00245,
      "epss_percentile": 0.15969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenBoxes",
      "cwe": "CWE-266",
      "title": "OpenBoxes Product Supplier Edit Controller RoleInterceptor.groovy improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14045"
    },
    {
      "rank": 966,
      "cve_id": "CVE-2024-14046",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00245,
      "epss_percentile": 0.15969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenBoxes",
      "cwe": "CWE-284",
      "title": "OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14046"
    },
    {
      "rank": 967,
      "cve_id": "CVE-2026-74947",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-763",
      "title": "Privilege escalation due to invalid pointer in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74947"
    },
    {
      "rank": 968,
      "cve_id": "CVE-2026-16309",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netiket Information Technologies",
      "product": "EdoWEB",
      "cwe": "CWE-639",
      "title": "IDOR in Netiket Information Technologies' EdoWEB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16309"
    },
    {
      "rank": 969,
      "cve_id": "CVE-2026-74003",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rometheme",
      "product": "RomethemeForm For Elementor",
      "cwe": "CWE-862",
      "title": "WordPress RomethemeForm For Elementor plugin <= 1.2.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74003"
    },
    {
      "rank": 970,
      "cve_id": "CVE-2021-43718",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00243,
      "epss_percentile": 0.15756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-43718"
    },
    {
      "rank": 971,
      "cve_id": "CVE-2026-70681",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications DBA",
      "cwe": null,
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and other Java utils). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70681"
    },
    {
      "rank": 972,
      "cve_id": "CVE-2026-62551",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62551"
    },
    {
      "rank": 973,
      "cve_id": "CVE-2026-60949",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60949"
    },
    {
      "rank": 974,
      "cve_id": "CVE-2026-62627",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62627"
    },
    {
      "rank": 975,
      "cve_id": "CVE-2026-70760",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70760"
    },
    {
      "rank": 976,
      "cve_id": "CVE-2026-15315",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 v5",
      "cwe": "CWE-287",
      "title": "Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15315"
    },
    {
      "rank": 977,
      "cve_id": "CVE-2026-73931",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73931"
    },
    {
      "rank": 978,
      "cve_id": "CVE-2026-1199",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-362",
      "title": "API and Frontend login lockout race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1199"
    },
    {
      "rank": 979,
      "cve_id": "CVE-2026-61342",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61342"
    },
    {
      "rank": 980,
      "cve_id": "CVE-2026-67921",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00241,
      "epss_percentile": 0.15491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67921"
    },
    {
      "rank": 981,
      "cve_id": "CVE-2026-73925",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.1542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73925"
    },
    {
      "rank": 982,
      "cve_id": "CVE-2026-70801",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.1545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Flow Manufacturing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70801"
    },
    {
      "rank": 983,
      "cve_id": "CVE-2026-70677",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.1535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70677"
    },
    {
      "rank": 984,
      "cve_id": "CVE-2026-71165",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71165"
    },
    {
      "rank": 985,
      "cve_id": "CVE-2026-73881",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73881"
    },
    {
      "rank": 986,
      "cve_id": "CVE-2026-73913",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73913"
    },
    {
      "rank": 987,
      "cve_id": "CVE-2026-73919",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73919"
    },
    {
      "rank": 988,
      "cve_id": "CVE-2026-71087",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71087"
    },
    {
      "rank": 989,
      "cve_id": "CVE-2026-73871",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73871"
    },
    {
      "rank": 990,
      "cve_id": "CVE-2026-73872",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73872"
    },
    {
      "rank": 991,
      "cve_id": "CVE-2026-73900",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73900"
    },
    {
      "rank": 992,
      "cve_id": "CVE-2026-73910",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73910"
    },
    {
      "rank": 993,
      "cve_id": "CVE-2026-74007",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iberezansky",
      "product": "3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery",
      "cwe": "CWE-497",
      "title": "WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74007"
    },
    {
      "rank": 994,
      "cve_id": "CVE-2026-74008",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "averta",
      "product": "Shortcodes and extra features for Phlox theme",
      "cwe": "CWE-201",
      "title": "WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74008"
    },
    {
      "rank": 995,
      "cve_id": "CVE-2026-34884",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00238,
      "epss_percentile": 0.15077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache SkyWalking MCP",
      "cwe": "CWE-918",
      "title": "Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34884"
    },
    {
      "rank": 996,
      "cve_id": "CVE-2026-60757",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM End User",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Search). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM End User executes to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60757"
    },
    {
      "rank": 997,
      "cve_id": "CVE-2026-60791",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60791"
    },
    {
      "rank": 998,
      "cve_id": "CVE-2026-70943",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70943"
    },
    {
      "rank": 999,
      "cve_id": "CVE-2026-62568",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62568"
    },
    {
      "rank": 1000,
      "cve_id": "CVE-2026-70765",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70765"
    },
    {
      "rank": 1001,
      "cve_id": "CVE-2026-70768",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70768"
    },
    {
      "rank": 1002,
      "cve_id": "CVE-2026-70961",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70961"
    },
    {
      "rank": 1003,
      "cve_id": "CVE-2026-71019",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Internal operations). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71019"
    },
    {
      "rank": 1004,
      "cve_id": "CVE-2026-73898",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73898"
    },
    {
      "rank": 1005,
      "cve_id": "CVE-2026-70759",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70759"
    },
    {
      "rank": 1006,
      "cve_id": "CVE-2026-70766",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70766"
    },
    {
      "rank": 1007,
      "cve_id": "CVE-2026-71123",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71123"
    },
    {
      "rank": 1008,
      "cve_id": "CVE-2026-32547",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "BP Better Messages",
      "cwe": "CWE-79",
      "title": "WordPress BP Better Messages plugin <= 2.15.22 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32547"
    },
    {
      "rank": 1009,
      "cve_id": "CVE-2026-66621",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ultimate Dashboad",
      "product": "Ultimate Dashboard",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate Dashboard plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66621"
    },
    {
      "rank": 1010,
      "cve_id": "CVE-2026-66629",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-79",
      "title": "WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66629"
    },
    {
      "rank": 1011,
      "cve_id": "CVE-2026-68567",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Grids",
      "product": "Convert Pro",
      "cwe": "CWE-79",
      "title": "WordPress Convert Pro plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68567"
    },
    {
      "rank": 1012,
      "cve_id": "CVE-2026-73338",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autopay",
      "product": "Autopay",
      "cwe": "CWE-79",
      "title": "WordPress Autopay plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73338"
    },
    {
      "rank": 1013,
      "cve_id": "CVE-2026-73342",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magazine3",
      "product": "WP Multilang",
      "cwe": "CWE-79",
      "title": "WordPress WP Multilang plugin <= 2.4.31 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73342"
    },
    {
      "rank": 1014,
      "cve_id": "CVE-2026-73358",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.1494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Affiliates Manager",
      "cwe": "CWE-79",
      "title": "WordPress Affiliates Manager plugin <= 2.9.53 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73358"
    },
    {
      "rank": 1015,
      "cve_id": "CVE-2026-73360",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Premio",
      "product": "Chaty Pro",
      "cwe": "CWE-79",
      "title": "WordPress Chaty Pro plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73360"
    },
    {
      "rank": 1016,
      "cve_id": "CVE-2026-73362",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KaizenCoders",
      "product": "URL Shortify",
      "cwe": "CWE-79",
      "title": "WordPress URL Shortify plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73362"
    },
    {
      "rank": 1017,
      "cve_id": "CVE-2026-73378",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Contact Form by Supsystic",
      "cwe": "CWE-79",
      "title": "WordPress Contact Form by Supsystic plugin < 1.10.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73378"
    },
    {
      "rank": 1018,
      "cve_id": "CVE-2026-73382",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gemini Labs",
      "product": "Site Reviews",
      "cwe": "CWE-79",
      "title": "WordPress Site Reviews plugin <= 8.2.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73382"
    },
    {
      "rank": 1019,
      "cve_id": "CVE-2026-73393",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "Subscribe2",
      "cwe": "CWE-79",
      "title": "WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73393"
    },
    {
      "rank": 1020,
      "cve_id": "CVE-2026-66780",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-284",
      "title": "Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66780"
    },
    {
      "rank": 1021,
      "cve_id": "CVE-2026-48508",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-863",
      "title": "Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48508"
    },
    {
      "rank": 1022,
      "cve_id": "CVE-2026-71096",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71096"
    },
    {
      "rank": 1023,
      "cve_id": "CVE-2026-62529",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00235,
      "epss_percentile": 0.14681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62529"
    },
    {
      "rank": 1024,
      "cve_id": "CVE-2026-28192",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piotnet",
      "product": "Piotnet Addons For Elementor Pro",
      "cwe": "CWE-434",
      "title": "WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28192"
    },
    {
      "rank": 1025,
      "cve_id": "CVE-2026-67262",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.1454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-862",
      "title": "Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67262"
    },
    {
      "rank": 1026,
      "cve_id": "CVE-2026-70858",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70858"
    },
    {
      "rank": 1027,
      "cve_id": "CVE-2026-55164",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-256",
      "title": "Lemur: Plaintext password storage in Lemur user-update path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55164"
    },
    {
      "rank": 1028,
      "cve_id": "CVE-2026-71307",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-862",
      "title": "Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71307"
    },
    {
      "rank": 1029,
      "cve_id": "CVE-2026-75844",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-918",
      "title": "ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75844"
    },
    {
      "rank": 1030,
      "cve_id": "CVE-2026-55593",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-352",
      "title": "Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery Protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55593"
    },
    {
      "rank": 1031,
      "cve_id": "CVE-2026-74952",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Application Update component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74952"
    },
    {
      "rank": 1032,
      "cve_id": "CVE-2026-73891",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73891"
    },
    {
      "rank": 1033,
      "cve_id": "CVE-2026-73933",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73933"
    },
    {
      "rank": 1034,
      "cve_id": "CVE-2026-71155",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71155"
    },
    {
      "rank": 1035,
      "cve_id": "CVE-2026-61696",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forem",
      "product": "forem",
      "cwe": "CWE-74",
      "title": "Forem: Stored XSS in Admin Abuse Report Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61696"
    },
    {
      "rank": 1036,
      "cve_id": "CVE-2026-62606",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.14105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62606"
    },
    {
      "rank": 1037,
      "cve_id": "CVE-2026-71108",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71108"
    },
    {
      "rank": 1038,
      "cve_id": "CVE-2026-62520",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62520"
    },
    {
      "rank": 1039,
      "cve_id": "CVE-2021-43717",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00229,
      "epss_percentile": 0.13946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-43717"
    },
    {
      "rank": 1040,
      "cve_id": "CVE-2026-62448",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Email Center",
      "cwe": null,
      "title": "Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Component). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62448"
    },
    {
      "rank": 1041,
      "cve_id": "CVE-2026-62605",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Partner Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Partner Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62605"
    },
    {
      "rank": 1042,
      "cve_id": "CVE-2026-71016",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71016"
    },
    {
      "rank": 1043,
      "cve_id": "CVE-2026-62603",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62603"
    },
    {
      "rank": 1044,
      "cve_id": "CVE-2026-70843",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70843"
    },
    {
      "rank": 1045,
      "cve_id": "CVE-2026-70853",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70853"
    },
    {
      "rank": 1046,
      "cve_id": "CVE-2026-62459",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62459"
    },
    {
      "rank": 1047,
      "cve_id": "CVE-2026-71156",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71156"
    },
    {
      "rank": 1048,
      "cve_id": "CVE-2026-62613",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00225,
      "epss_percentile": 0.13459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62613"
    },
    {
      "rank": 1049,
      "cve_id": "CVE-2026-62637",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00225,
      "epss_percentile": 0.13459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62637"
    },
    {
      "rank": 1050,
      "cve_id": "CVE-2026-75835",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00224,
      "epss_percentile": 0.1333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav API Plugin before 1.0.14 Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75835"
    },
    {
      "rank": 1051,
      "cve_id": "CVE-2026-74950",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Downloads API component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74950"
    },
    {
      "rank": 1052,
      "cve_id": "CVE-2026-74955",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Request Handling component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74955"
    },
    {
      "rank": 1053,
      "cve_id": "CVE-2026-52606",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52606"
    },
    {
      "rank": 1054,
      "cve_id": "CVE-2026-52609",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52609"
    },
    {
      "rank": 1055,
      "cve_id": "CVE-2026-45120",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-639",
      "title": "MyBB: Insufficient authorization for private calendar events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45120"
    },
    {
      "rank": 1056,
      "cve_id": "CVE-2026-75839",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-200",
      "title": "ArcadeDB before 26.8.1 Information Disclosure via Cluster Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75839"
    },
    {
      "rank": 1057,
      "cve_id": "CVE-2026-75832",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00222,
      "epss_percentile": 0.13008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav API Plugin before 1.0.14 Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75832"
    },
    {
      "rank": 1058,
      "cve_id": "CVE-2026-52723",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0022,
      "epss_percentile": 0.12801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fbeta-GmbH",
      "product": "ePA3-Service-OpenSource",
      "cwe": "CWE-295",
      "title": "ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52723"
    },
    {
      "rank": 1059,
      "cve_id": "CVE-2026-74004",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmonks",
      "product": "Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms",
      "cwe": "CWE-862",
      "title": "WordPress Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74004"
    },
    {
      "rank": 1060,
      "cve_id": "CVE-2026-71118",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.1273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71118"
    },
    {
      "rank": 1061,
      "cve_id": "CVE-2026-62576",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62576"
    },
    {
      "rank": 1062,
      "cve_id": "CVE-2026-55166",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00217,
      "epss_percentile": 0.1245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-285",
      "title": "Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55166"
    },
    {
      "rank": 1063,
      "cve_id": "CVE-2026-62602",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62602"
    },
    {
      "rank": 1064,
      "cve_id": "CVE-2026-62545",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62545"
    },
    {
      "rank": 1065,
      "cve_id": "CVE-2026-70691",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70691"
    },
    {
      "rank": 1066,
      "cve_id": "CVE-2026-70955",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Platform",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Commerce Platform executes to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70955"
    },
    {
      "rank": 1067,
      "cve_id": "CVE-2026-73973",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-22",
      "title": "Linuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined --filename in logfile plugin (sudoers LPE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73973"
    },
    {
      "rank": 1068,
      "cve_id": "CVE-2026-76037",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-59",
      "title": "Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76037"
    },
    {
      "rank": 1069,
      "cve_id": "CVE-2026-71303",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-918",
      "title": "Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71303"
    },
    {
      "rank": 1070,
      "cve_id": "CVE-2026-66636",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Marcin",
      "product": "Wise Chat",
      "cwe": "CWE-79",
      "title": "WordPress Wise Chat plugin <= 3.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66636"
    },
    {
      "rank": 1071,
      "cve_id": "CVE-2026-66638",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shabti Kaplan",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-79",
      "title": "WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66638"
    },
    {
      "rank": 1072,
      "cve_id": "CVE-2026-66639",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPZOOM",
      "product": "WPZOOM Forms – Contact Form Plugin for Gutenberg",
      "cwe": "CWE-79",
      "title": "WordPress WPZOOM Forms – Contact Form plugin for Gutenberg plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66639"
    },
    {
      "rank": 1073,
      "cve_id": "CVE-2026-66640",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Marcus (aka @msykes)",
      "product": "Login With Ajax",
      "cwe": "CWE-79",
      "title": "WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66640"
    },
    {
      "rank": 1074,
      "cve_id": "CVE-2026-66643",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wronganswersonly",
      "product": "Wufoo Shortcode",
      "cwe": "CWE-79",
      "title": "WordPress Wufoo Shortcode plugin <= 1.55 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66643"
    },
    {
      "rank": 1075,
      "cve_id": "CVE-2026-66645",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "Table Of Contents Block",
      "cwe": "CWE-79",
      "title": "WordPress Table Of Contents Block plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66645"
    },
    {
      "rank": 1076,
      "cve_id": "CVE-2026-66646",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyThemeShop",
      "product": "WP Tab Widget",
      "cwe": "CWE-79",
      "title": "WordPress WP Tab Widget plugin <= 1.2.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66646"
    },
    {
      "rank": 1077,
      "cve_id": "CVE-2026-73359",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Legal Pages",
      "product": "WP Cookie Notice for GDPR, CCPA & ePrivacy Consent",
      "cwe": "CWE-79",
      "title": "WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.3.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73359"
    },
    {
      "rank": 1078,
      "cve_id": "CVE-2026-71147",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71147"
    },
    {
      "rank": 1079,
      "cve_id": "CVE-2026-73379",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Contact Form by Supsystic",
      "cwe": "CWE-288",
      "title": "WordPress Contact Form by Supsystic plugin < 1.10.0 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73379"
    },
    {
      "rank": 1080,
      "cve_id": "CVE-2026-74903",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-400",
      "title": "SiYuan before v3.7.4 Insufficient Access Control via spinBlockDOM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74903"
    },
    {
      "rank": 1081,
      "cve_id": "CVE-2026-75845",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.1137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-269",
      "title": "ArcadeDB 26.4.2 before 26.8.1 Authorization Bypass via set_server_setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75845"
    },
    {
      "rank": 1082,
      "cve_id": "CVE-2025-11729",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.1135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "buildwps",
      "product": "PPWP – Password Protect Pages",
      "cwe": "CWE-285",
      "title": "PPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Improper Authorization To Authenticated (Contributor+) Master Password Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11729"
    },
    {
      "rank": 1083,
      "cve_id": "CVE-2026-24185",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NVOS",
      "cwe": "CWE-288",
      "title": "NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24185"
    },
    {
      "rank": 1084,
      "cve_id": "CVE-2026-70682",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00208,
      "epss_percentile": 0.11251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70682"
    },
    {
      "rank": 1085,
      "cve_id": "CVE-2026-70785",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00208,
      "epss_percentile": 0.11251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70785"
    },
    {
      "rank": 1086,
      "cve_id": "CVE-2026-15371",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-177",
      "title": "Velociraptor Stored XSS in URL column types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15371"
    },
    {
      "rank": 1087,
      "cve_id": "CVE-2026-67846",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00207,
      "epss_percentile": 0.11139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicit local satp.MODE validity check at the use site",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67846"
    },
    {
      "rank": 1088,
      "cve_id": "CVE-2026-71539",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.11027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-367",
      "title": "n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71539"
    },
    {
      "rank": 1089,
      "cve_id": "CVE-2026-70674",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Reports Developer",
      "cwe": null,
      "title": "Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70674"
    },
    {
      "rank": 1090,
      "cve_id": "CVE-2026-61139",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials (International)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials (International) accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials (International) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61139"
    },
    {
      "rank": 1091,
      "cve_id": "CVE-2026-71030",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71030"
    },
    {
      "rank": 1092,
      "cve_id": "CVE-2026-73892",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73892"
    },
    {
      "rank": 1093,
      "cve_id": "CVE-2026-73904",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73904"
    },
    {
      "rank": 1094,
      "cve_id": "CVE-2026-12520",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12520"
    },
    {
      "rank": 1095,
      "cve_id": "CVE-2026-63640",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MagicMirrorOrg",
      "product": "MagicMirror",
      "cwe": "CWE-200",
      "title": "MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63640"
    },
    {
      "rank": 1096,
      "cve_id": "CVE-2026-61296",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Linear Asset Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Asset Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61296"
    },
    {
      "rank": 1097,
      "cve_id": "CVE-2026-70678",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70678"
    },
    {
      "rank": 1098,
      "cve_id": "CVE-2026-71020",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71020"
    },
    {
      "rank": 1099,
      "cve_id": "CVE-2026-71021",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71021"
    },
    {
      "rank": 1100,
      "cve_id": "CVE-2026-71022",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71022"
    },
    {
      "rank": 1101,
      "cve_id": "CVE-2026-62522",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62522"
    },
    {
      "rank": 1102,
      "cve_id": "CVE-2026-75088",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.1076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewbilling.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75088"
    },
    {
      "rank": 1103,
      "cve_id": "CVE-2026-52737",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.1062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-345",
      "title": "ZEBRA: Sync restart poisoning from single unauthenticated peer via above-lookahead block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52737"
    },
    {
      "rank": 1104,
      "cve_id": "CVE-2026-71071",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71071"
    },
    {
      "rank": 1105,
      "cve_id": "CVE-2021-43716",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00203,
      "epss_percentile": 0.10561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-43716"
    },
    {
      "rank": 1106,
      "cve_id": "CVE-2026-75625",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.002,
      "epss_percentile": 0.10222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uber",
      "product": "kraken",
      "cwe": "CWE-354",
      "title": "Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75625"
    },
    {
      "rank": 1107,
      "cve_id": "CVE-2026-75086",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewroom.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75086"
    },
    {
      "rank": 1108,
      "cve_id": "CVE-2026-75087",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewdepartment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75087"
    },
    {
      "rank": 1109,
      "cve_id": "CVE-2026-23933",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-259",
      "title": "Hardcoded session key in Zabbix 7.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23933"
    },
    {
      "rank": 1110,
      "cve_id": "CVE-2026-74943",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00199,
      "epss_percentile": 0.10122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Use-after-free in the Graphics: ImageLib component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74943"
    },
    {
      "rank": 1111,
      "cve_id": "CVE-2026-74945",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00199,
      "epss_percentile": 0.10122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Information disclosure in the Graphics: Text component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74945"
    },
    {
      "rank": 1112,
      "cve_id": "CVE-2026-73923",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73923"
    },
    {
      "rank": 1113,
      "cve_id": "CVE-2026-55426",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-78",
      "title": "linuxfabrik-lib: Local privilege escalation using embedded command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55426"
    },
    {
      "rank": 1114,
      "cve_id": "CVE-2026-32467",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apoyl",
      "product": "[Aotuman] Grab WeChat Articles",
      "cwe": "CWE-918",
      "title": "WordPress [Aotuman] Grab WeChat Articles plugin <= 2.0.1 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32467"
    },
    {
      "rank": 1115,
      "cve_id": "CVE-2026-75032",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75032"
    },
    {
      "rank": 1116,
      "cve_id": "CVE-2026-70963",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70963"
    },
    {
      "rank": 1117,
      "cve_id": "CVE-2026-73873",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73873"
    },
    {
      "rank": 1118,
      "cve_id": "CVE-2026-62461",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62461"
    },
    {
      "rank": 1119,
      "cve_id": "CVE-2026-75833",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-601",
      "title": "Grav API Plugin Open Redirect via Backslash Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75833"
    },
    {
      "rank": 1120,
      "cve_id": "CVE-2026-75091",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mdmag",
      "product": "Quill Forms | Conversational Multi Step Forms, Surveys & quizzes",
      "cwe": "CWE-79",
      "title": "Quill Forms <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75091"
    },
    {
      "rank": 1121,
      "cve_id": "CVE-2026-66651",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MultiVendorX",
      "product": "MultiVendorX",
      "cwe": "CWE-862",
      "title": "WordPress MultiVendorX plugin <= 5.0.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66651"
    },
    {
      "rank": 1122,
      "cve_id": "CVE-2026-73348",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-862",
      "title": "WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73348"
    },
    {
      "rank": 1123,
      "cve_id": "CVE-2026-17106",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "go-archive",
      "cwe": "CWE-59",
      "title": "Tar extraction in moby/go-archive can write outside the destination directory via link following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17106"
    },
    {
      "rank": 1124,
      "cve_id": "CVE-2026-68923",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MobSF",
      "product": "Mobile-Security-Framework-MobSF",
      "cwe": "CWE-352",
      "title": "MobSF: CSRF checks not enforced after Django migration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68923"
    },
    {
      "rank": 1125,
      "cve_id": "CVE-2026-70789",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70789"
    },
    {
      "rank": 1126,
      "cve_id": "CVE-2026-70776",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00193,
      "epss_percentile": 0.09398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70776"
    },
    {
      "rank": 1127,
      "cve_id": "CVE-2026-70717",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Autonomous Health Framework",
      "cwe": null,
      "title": "Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Autonomous Health Framework accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70717"
    },
    {
      "rank": 1128,
      "cve_id": "CVE-2026-70780",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70780"
    },
    {
      "rank": 1129,
      "cve_id": "CVE-2026-70923",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70923"
    },
    {
      "rank": 1130,
      "cve_id": "CVE-2026-62604",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62604"
    },
    {
      "rank": 1131,
      "cve_id": "CVE-2026-53456",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ha-china",
      "product": "blueprint-studio",
      "cwe": "CWE-522",
      "title": "Blueprint Studio terminal SSH private key written to disk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53456"
    },
    {
      "rank": 1132,
      "cve_id": "CVE-2026-15316",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 v5",
      "cwe": "CWE-20",
      "title": "Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15316"
    },
    {
      "rank": 1133,
      "cve_id": "CVE-2026-52817",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-88",
      "title": "Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52817"
    },
    {
      "rank": 1134,
      "cve_id": "CVE-2026-74973",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-362",
      "title": "Race condition, use-after-free in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74973"
    },
    {
      "rank": 1135,
      "cve_id": "CVE-2026-50578",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fbeta-GmbH",
      "product": "ePA3-Service-OpenSource",
      "cwe": "CWE-295",
      "title": "ePA 3.x Integration: TLS Certificate Verification Universally Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50578"
    },
    {
      "rank": 1136,
      "cve_id": "CVE-2026-74006",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Table Builder",
      "product": "WP Table Builder",
      "cwe": "CWE-862",
      "title": "WordPress WP Table Builder plugin <= 2.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74006"
    },
    {
      "rank": 1137,
      "cve_id": "CVE-2026-74987",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00184,
      "epss_percentile": 0.08356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74987"
    },
    {
      "rank": 1138,
      "cve_id": "CVE-2026-71676",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when the message type byte of a NAS PDU is mutated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71676"
    },
    {
      "rank": 1139,
      "cve_id": "CVE-2026-53759",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00184,
      "epss_percentile": 0.0827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-377",
      "title": "linuxfabrik-lib: Insecure creation of SQLite databases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53759"
    },
    {
      "rank": 1140,
      "cve_id": "CVE-2026-73874",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73874"
    },
    {
      "rank": 1141,
      "cve_id": "CVE-2026-73911",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73911"
    },
    {
      "rank": 1142,
      "cve_id": "CVE-2026-60961",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60961"
    },
    {
      "rank": 1143,
      "cve_id": "CVE-2026-62578",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62578"
    },
    {
      "rank": 1144,
      "cve_id": "CVE-2026-63336",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-295",
      "title": "RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63336"
    },
    {
      "rank": 1145,
      "cve_id": "CVE-2026-74908",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav plugin-api before 1.0.15 Script Injection via SVG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74908"
    },
    {
      "rank": 1146,
      "cve_id": "CVE-2026-75834",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75834"
    },
    {
      "rank": 1147,
      "cve_id": "CVE-2026-52481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the tcp_actions() function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52481"
    },
    {
      "rank": 1148,
      "cve_id": "CVE-2026-71675",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.0798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-401",
      "title": "An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71675"
    },
    {
      "rank": 1149,
      "cve_id": "CVE-2026-71004",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71004"
    },
    {
      "rank": 1150,
      "cve_id": "CVE-2026-71005",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71005"
    },
    {
      "rank": 1151,
      "cve_id": "CVE-2026-71006",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71006"
    },
    {
      "rank": 1152,
      "cve_id": "CVE-2026-71011",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71011"
    },
    {
      "rank": 1153,
      "cve_id": "CVE-2026-71025",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71025"
    },
    {
      "rank": 1154,
      "cve_id": "CVE-2026-71031",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71031"
    },
    {
      "rank": 1155,
      "cve_id": "CVE-2026-73869",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73869"
    },
    {
      "rank": 1156,
      "cve_id": "CVE-2026-73870",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73870"
    },
    {
      "rank": 1157,
      "cve_id": "CVE-2026-52480",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00181,
      "epss_percentile": 0.0798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52480"
    },
    {
      "rank": 1158,
      "cve_id": "CVE-2026-28568",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mohamed Magdy",
      "product": "Quill Forms",
      "cwe": "CWE-79",
      "title": "WordPress Quill Forms plugin <= 5.7.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28568"
    },
    {
      "rank": 1159,
      "cve_id": "CVE-2026-28569",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SSL Zen",
      "product": "SSL Zen",
      "cwe": "CWE-79",
      "title": "WordPress SSL Zen plugin <= 4.7.43 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28569"
    },
    {
      "rank": 1160,
      "cve_id": "CVE-2026-32333",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeconceTheme",
      "product": "Mayosis Core",
      "cwe": "CWE-79",
      "title": "WordPress Mayosis Core plugin <= 5.4.7 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32333"
    },
    {
      "rank": 1161,
      "cve_id": "CVE-2026-66633",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Fluent Forms Pro Add On Pack",
      "cwe": "CWE-79",
      "title": "WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66633"
    },
    {
      "rank": 1162,
      "cve_id": "CVE-2026-66667",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "Templately",
      "cwe": "CWE-79",
      "title": "WordPress Templately plugin <= 3.7.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66667"
    },
    {
      "rank": 1163,
      "cve_id": "CVE-2026-73190",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shahjada",
      "product": "WPDM – Premium Packages",
      "cwe": "CWE-79",
      "title": "WordPress WPDM – Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73190"
    },
    {
      "rank": 1164,
      "cve_id": "CVE-2026-73351",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "WordPress Social Login and Register",
      "cwe": "CWE-79",
      "title": "WordPress WordPress Social Login and Register plugin <= 7.8.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73351"
    },
    {
      "rank": 1165,
      "cve_id": "CVE-2026-73361",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPZOOM",
      "product": "Recipe Card Blocks for Gutenberg & Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.18 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73361"
    },
    {
      "rank": 1166,
      "cve_id": "CVE-2026-73375",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supsystic",
      "product": "Ultimate Maps by Supsystic",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73375"
    },
    {
      "rank": 1167,
      "cve_id": "CVE-2026-71077",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71077"
    },
    {
      "rank": 1168,
      "cve_id": "CVE-2026-71308",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-639",
      "title": "Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71308"
    },
    {
      "rank": 1169,
      "cve_id": "CVE-2026-71322",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-862",
      "title": "Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71322"
    },
    {
      "rank": 1170,
      "cve_id": "CVE-2026-70709",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70709"
    },
    {
      "rank": 1171,
      "cve_id": "CVE-2026-73901",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73901"
    },
    {
      "rank": 1172,
      "cve_id": "CVE-2026-71075",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.0746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71075"
    },
    {
      "rank": 1173,
      "cve_id": "CVE-2026-75911",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-94",
      "title": "CodeWhale before 0.8.64 Remote Code Execution via allow_shell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75911"
    },
    {
      "rank": 1174,
      "cve_id": "CVE-2026-23935",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-125",
      "title": "Use-after-free read in script item/preprocessing HttpRequest body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23935"
    },
    {
      "rank": 1175,
      "cve_id": "CVE-2026-19670",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CISAgov",
      "product": "Malcolm",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in CISA Malcolm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19670"
    },
    {
      "rank": 1176,
      "cve_id": "CVE-2026-60884",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60884"
    },
    {
      "rank": 1177,
      "cve_id": "CVE-2026-71145",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.0713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71145"
    },
    {
      "rank": 1178,
      "cve_id": "CVE-2026-50575",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UNITRONIX",
      "product": "BetterDesk",
      "cwe": "CWE-294",
      "title": "BetterDesk has a replay behavior vulnerability when devices are deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50575"
    },
    {
      "rank": 1179,
      "cve_id": "CVE-2026-74975",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-451",
      "title": "Spoofing issue in the Downloads component in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74975"
    },
    {
      "rank": 1180,
      "cve_id": "CVE-2026-23930",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-405",
      "title": "Frontend DoS via the popup.testtriggerexpr action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23930"
    },
    {
      "rank": 1181,
      "cve_id": "CVE-2026-74983",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the Data Loss Prevention component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74983"
    },
    {
      "rank": 1182,
      "cve_id": "CVE-2026-60993",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60993"
    },
    {
      "rank": 1183,
      "cve_id": "CVE-2026-54552",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amoffat",
      "product": "sh",
      "cwe": "CWE-273",
      "title": "sh _uid does not drop supplementary groups (incomplete privilege drop)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54552"
    },
    {
      "rank": 1184,
      "cve_id": "CVE-2026-74951",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-1021",
      "title": "Clickjacking issue in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74951"
    },
    {
      "rank": 1185,
      "cve_id": "CVE-2026-74970",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Site isolation issue in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74970"
    },
    {
      "rank": 1186,
      "cve_id": "CVE-2026-23934",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-405",
      "title": "Frontend DoS via the validate.api.exists action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23934"
    },
    {
      "rank": 1187,
      "cve_id": "CVE-2026-75107",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav Form Plugin before 9.1.19 Stored XSS via Field Properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75107"
    },
    {
      "rank": 1188,
      "cve_id": "CVE-2026-63632",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onnx",
      "product": "onnx",
      "cwe": "CWE-125",
      "title": "ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63632"
    },
    {
      "rank": 1189,
      "cve_id": "CVE-2026-68939",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pyenv",
      "product": "pyenv",
      "cwe": "CWE-78",
      "title": "Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68939"
    },
    {
      "rank": 1190,
      "cve_id": "CVE-2026-70666",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-918",
      "title": "Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70666"
    },
    {
      "rank": 1191,
      "cve_id": "CVE-2026-55162",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-918",
      "title": "Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55162"
    },
    {
      "rank": 1192,
      "cve_id": "CVE-2026-55163",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-863",
      "title": "Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55163"
    },
    {
      "rank": 1193,
      "cve_id": "CVE-2026-70793",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70793"
    },
    {
      "rank": 1194,
      "cve_id": "CVE-2026-66635",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "Slider by 10Web",
      "cwe": "CWE-352",
      "title": "WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66635"
    },
    {
      "rank": 1195,
      "cve_id": "CVE-2026-74957",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.06088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Mitigation bypass in the Safe Browsing component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74957"
    },
    {
      "rank": 1196,
      "cve_id": "CVE-2026-74959",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.06089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Mitigation bypass in the Storage: Cache API component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74959"
    },
    {
      "rank": 1197,
      "cve_id": "CVE-2026-74976",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-843",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74976"
    },
    {
      "rank": 1198,
      "cve_id": "CVE-2026-62454",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62454"
    },
    {
      "rank": 1199,
      "cve_id": "CVE-2026-71551",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "super-productivity",
      "product": "super-productivity",
      "cwe": "CWE-78",
      "title": "Super Productivity: Arbitrary OS Command Execution via IPC EXEC Handler with Persistent Whitelist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71551"
    },
    {
      "rank": 1200,
      "cve_id": "CVE-2026-70894",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70894"
    },
    {
      "rank": 1201,
      "cve_id": "CVE-2026-61295",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61295"
    },
    {
      "rank": 1202,
      "cve_id": "CVE-2026-19447",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fileorbis Informatics Services Trade Inc.",
      "product": "FileOrbis",
      "cwe": "CWE-79",
      "title": "Stored XSS in Fileorbis Informatics's FileOrbis",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19447"
    },
    {
      "rank": 1203,
      "cve_id": "CVE-2026-62291",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62291"
    },
    {
      "rank": 1204,
      "cve_id": "CVE-2026-66591",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-79",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.39 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66591"
    },
    {
      "rank": 1205,
      "cve_id": "CVE-2026-66603",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Artiss",
      "product": "Draft List",
      "cwe": "CWE-79",
      "title": "WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66603"
    },
    {
      "rank": 1206,
      "cve_id": "CVE-2026-66637",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alex",
      "product": "Featured Video Plus",
      "cwe": "CWE-79",
      "title": "WordPress Featured Video Plus plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66637"
    },
    {
      "rank": 1207,
      "cve_id": "CVE-2026-66641",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deepen Bajracharya",
      "product": "Video Conferencing with Zoom",
      "cwe": "CWE-79",
      "title": "WordPress Video Conferencing with Zoom plugin <= 4.6.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66641"
    },
    {
      "rank": 1208,
      "cve_id": "CVE-2026-66644",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "93digital",
      "product": "Typing Effect",
      "cwe": "CWE-79",
      "title": "WordPress Typing Effect plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66644"
    },
    {
      "rank": 1209,
      "cve_id": "CVE-2026-68565",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-79",
      "title": "WordPress GeoDirectory plugin <= 2.8.172 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68565"
    },
    {
      "rank": 1210,
      "cve_id": "CVE-2026-74969",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Layout: Text and Fonts component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74969"
    },
    {
      "rank": 1211,
      "cve_id": "CVE-2026-70840",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70840"
    },
    {
      "rank": 1212,
      "cve_id": "CVE-2026-70842",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70842"
    },
    {
      "rank": 1213,
      "cve_id": "CVE-2026-70719",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70719"
    },
    {
      "rank": 1214,
      "cve_id": "CVE-2026-70917",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70917"
    },
    {
      "rank": 1215,
      "cve_id": "CVE-2026-75850",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0016,
      "epss_percentile": 0.05711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-862",
      "title": "ArcadeDB before 26.8.1 Per-Type ACL Bypass via Batch Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75850"
    },
    {
      "rank": 1216,
      "cve_id": "CVE-2026-74934",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0016,
      "epss_percentile": 0.05687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the Graphics: CanvasWebGL component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74934"
    },
    {
      "rank": 1217,
      "cve_id": "CVE-2026-74940",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0016,
      "epss_percentile": 0.05688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Use-after-free in the Graphics: Text component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74940"
    },
    {
      "rank": 1218,
      "cve_id": "CVE-2026-74948",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0016,
      "epss_percentile": 0.05687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Information disclosure in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74948"
    },
    {
      "rank": 1219,
      "cve_id": "CVE-2026-75924",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-269",
      "title": "Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants cluster-wide secret read/write and csr approval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75924"
    },
    {
      "rank": 1220,
      "cve_id": "CVE-2026-71131",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71131"
    },
    {
      "rank": 1221,
      "cve_id": "CVE-2026-60392",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Outside In Technology",
      "cwe": "CWE-502",
      "title": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60392"
    },
    {
      "rank": 1222,
      "cve_id": "CVE-2026-60412",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.0556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Outside In Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60412"
    },
    {
      "rank": 1223,
      "cve_id": "CVE-2026-60413",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Outside In Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60413"
    },
    {
      "rank": 1224,
      "cve_id": "CVE-2026-60414",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.0556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Outside In Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60414"
    },
    {
      "rank": 1225,
      "cve_id": "CVE-2026-71010",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.0556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71010"
    },
    {
      "rank": 1226,
      "cve_id": "CVE-2026-70698",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70698"
    },
    {
      "rank": 1227,
      "cve_id": "CVE-2026-71109",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71109"
    },
    {
      "rank": 1228,
      "cve_id": "CVE-2026-74964",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00156,
      "epss_percentile": 0.05321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "title": "Integer overflow in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74964"
    },
    {
      "rank": 1229,
      "cve_id": "CVE-2026-74962",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.0532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Site isolation issue in the Networking: Cookies component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74962"
    },
    {
      "rank": 1230,
      "cve_id": "CVE-2026-71084",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71084"
    },
    {
      "rank": 1231,
      "cve_id": "CVE-2026-74936",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Use-after-free in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74936"
    },
    {
      "rank": 1232,
      "cve_id": "CVE-2026-74944",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74944"
    },
    {
      "rank": 1233,
      "cve_id": "CVE-2026-74960",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the WebExtensions component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74960"
    },
    {
      "rank": 1234,
      "cve_id": "CVE-2025-9210",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Otalio",
      "product": "Ship Property Management System",
      "cwe": "CWE-347",
      "title": "Missing JSON Web Token signature validation in Otalio Ship Property Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9210"
    },
    {
      "rank": 1235,
      "cve_id": "CVE-2026-70991",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70991"
    },
    {
      "rank": 1236,
      "cve_id": "CVE-2026-70726",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cash Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Cash Management executes to compromise Oracle Cash Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cash Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cash Management accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70726"
    },
    {
      "rank": 1237,
      "cve_id": "CVE-2026-71114",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71114"
    },
    {
      "rank": 1238,
      "cve_id": "CVE-2026-71115",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71115"
    },
    {
      "rank": 1239,
      "cve_id": "CVE-2026-75151",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Onlne Examination & Learning Management System",
      "cwe": "CWE-352",
      "title": "SourceCodester Onlne Examination & Learning Management System cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75151"
    },
    {
      "rank": 1240,
      "cve_id": "CVE-2026-73880",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73880"
    },
    {
      "rank": 1241,
      "cve_id": "CVE-2026-74988",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.05097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74988"
    },
    {
      "rank": 1242,
      "cve_id": "CVE-2026-52876",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.0495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-20",
      "title": "Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52876"
    },
    {
      "rank": 1243,
      "cve_id": "CVE-2026-61313",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 6.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61313"
    },
    {
      "rank": 1244,
      "cve_id": "CVE-2026-71080",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71080"
    },
    {
      "rank": 1245,
      "cve_id": "CVE-2026-70941",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": null,
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70941"
    },
    {
      "rank": 1246,
      "cve_id": "CVE-2026-71051",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Product Lifecycle Analytics",
      "cwe": null,
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71051"
    },
    {
      "rank": 1247,
      "cve_id": "CVE-2026-60753",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60753"
    },
    {
      "rank": 1248,
      "cve_id": "CVE-2026-60822",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager for Systems Infrastructure",
      "cwe": null,
      "title": "Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager for Systems Infrastructure executes to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60822"
    },
    {
      "rank": 1249,
      "cve_id": "CVE-2026-60991",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60991"
    },
    {
      "rank": 1250,
      "cve_id": "CVE-2026-61291",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61291"
    },
    {
      "rank": 1251,
      "cve_id": "CVE-2026-70750",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70750"
    },
    {
      "rank": 1252,
      "cve_id": "CVE-2026-70866",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Testing Suite",
      "cwe": null,
      "title": "Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70866"
    },
    {
      "rank": 1253,
      "cve_id": "CVE-2026-71028",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71028"
    },
    {
      "rank": 1254,
      "cve_id": "CVE-2026-71097",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71097"
    },
    {
      "rank": 1255,
      "cve_id": "CVE-2026-71111",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager executes to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71111"
    },
    {
      "rank": 1256,
      "cve_id": "CVE-2026-63328",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aquasecurity",
      "product": "trivy",
      "cwe": "CWE-22",
      "title": "Trivy: Path Traversal in Trivy Plugin Manager Allows Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63328"
    },
    {
      "rank": 1257,
      "cve_id": "CVE-2026-62572",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62572"
    },
    {
      "rank": 1258,
      "cve_id": "CVE-2026-70847",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70847"
    },
    {
      "rank": 1259,
      "cve_id": "CVE-2026-70895",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70895"
    },
    {
      "rank": 1260,
      "cve_id": "CVE-2026-74974",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Same-origin policy bypass in the Graphics: ImageLib component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74974"
    },
    {
      "rank": 1261,
      "cve_id": "CVE-2026-74981",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the Audio/Video: Web Codecs component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74981"
    },
    {
      "rank": 1262,
      "cve_id": "CVE-2026-74982",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Denial-of-service in the Widget component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74982"
    },
    {
      "rank": 1263,
      "cve_id": "CVE-2026-74984",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Race condition in the JavaScript Engine component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74984"
    },
    {
      "rank": 1264,
      "cve_id": "CVE-2026-74985",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Privilege escalation in the Enterprise Policies component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74985"
    },
    {
      "rank": 1265,
      "cve_id": "CVE-2026-74986",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the CSS Parsing and Computation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74986"
    },
    {
      "rank": 1266,
      "cve_id": "CVE-2026-74989",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Internally found bugs fixed in Thunderbird 154",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74989"
    },
    {
      "rank": 1267,
      "cve_id": "CVE-2026-60928",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": null,
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60928"
    },
    {
      "rank": 1268,
      "cve_id": "CVE-2026-70734",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Autonomous Health Framework",
      "cwe": null,
      "title": "Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70734"
    },
    {
      "rank": 1269,
      "cve_id": "CVE-2026-62537",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62537"
    },
    {
      "rank": 1270,
      "cve_id": "CVE-2026-70936",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70936"
    },
    {
      "rank": 1271,
      "cve_id": "CVE-2026-70967",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70967"
    },
    {
      "rank": 1272,
      "cve_id": "CVE-2026-73073",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Arbitrary Ex Command Execution in C Omni-Completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73073"
    },
    {
      "rank": 1273,
      "cve_id": "CVE-2026-71141",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.0451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71141"
    },
    {
      "rank": 1274,
      "cve_id": "CVE-2026-12631",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-862",
      "title": "Broken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12631"
    },
    {
      "rank": 1275,
      "cve_id": "CVE-2026-70838",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70838"
    },
    {
      "rank": 1276,
      "cve_id": "CVE-2026-74902",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00147,
      "epss_percentile": 0.04476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74902"
    },
    {
      "rank": 1277,
      "cve_id": "CVE-2026-71089",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00147,
      "epss_percentile": 0.04447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71089"
    },
    {
      "rank": 1278,
      "cve_id": "CVE-2026-66602",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DevItems",
      "product": "HashBar – WordPress Notification Bar",
      "cwe": "CWE-352",
      "title": "WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66602"
    },
    {
      "rank": 1279,
      "cve_id": "CVE-2026-70800",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle SDP Number Portability",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes to compromise Oracle SDP Number Portability. While the vulnerability is in Oracle SDP Number Portability, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SDP Number Portability accessible data as well as unauthorized read access to a subset of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70800"
    },
    {
      "rank": 1280,
      "cve_id": "CVE-2026-71136",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71136"
    },
    {
      "rank": 1281,
      "cve_id": "CVE-2026-71138",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71138"
    },
    {
      "rank": 1282,
      "cve_id": "CVE-2026-5224",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kriptok Crypto and Information Technologies Industry Trade Inc.",
      "product": "Cryptosim",
      "cwe": "CWE-312",
      "title": "Sensitive Data Exposure in Kriptek Crypto's Cryptosim",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5224"
    },
    {
      "rank": 1283,
      "cve_id": "CVE-2026-75926",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00145,
      "epss_percentile": 0.04251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-1188",
      "title": "Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75926"
    },
    {
      "rank": 1284,
      "cve_id": "CVE-2026-70989",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70989"
    },
    {
      "rank": 1285,
      "cve_id": "CVE-2026-62553",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62553"
    },
    {
      "rank": 1286,
      "cve_id": "CVE-2026-62564",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62564"
    },
    {
      "rank": 1287,
      "cve_id": "CVE-2026-70836",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70836"
    },
    {
      "rank": 1288,
      "cve_id": "CVE-2026-52875",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-22",
      "title": "Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52875"
    },
    {
      "rank": 1289,
      "cve_id": "CVE-2026-16732",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify",
      "product": "fastify",
      "cwe": "CWE-348",
      "title": "fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16732"
    },
    {
      "rank": 1290,
      "cve_id": "CVE-2026-71128",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71128"
    },
    {
      "rank": 1291,
      "cve_id": "CVE-2026-71135",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71135"
    },
    {
      "rank": 1292,
      "cve_id": "CVE-2026-71139",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71139"
    },
    {
      "rank": 1293,
      "cve_id": "CVE-2026-62580",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00144,
      "epss_percentile": 0.04166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62580"
    },
    {
      "rank": 1294,
      "cve_id": "CVE-2026-71134",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71134"
    },
    {
      "rank": 1295,
      "cve_id": "CVE-2026-74961",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00143,
      "epss_percentile": 0.04138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Side-channel in the Web Audio component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74961"
    },
    {
      "rank": 1296,
      "cve_id": "CVE-2026-74966",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00143,
      "epss_percentile": 0.04138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Information disclosure in the Form Autofill component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74966"
    },
    {
      "rank": 1297,
      "cve_id": "CVE-2026-52872",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-22",
      "title": "Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52872"
    },
    {
      "rank": 1298,
      "cve_id": "CVE-2026-71125",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71125"
    },
    {
      "rank": 1299,
      "cve_id": "CVE-2026-71073",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Connectors",
      "cwe": null,
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71073"
    },
    {
      "rank": 1300,
      "cve_id": "CVE-2026-62569",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62569"
    },
    {
      "rank": 1301,
      "cve_id": "CVE-2026-47630",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-36",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47630"
    },
    {
      "rank": 1302,
      "cve_id": "CVE-2026-27365",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Series",
      "cwe": "CWE-79",
      "title": "WordPress PublishPress Series plugin <= 2.17.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27365"
    },
    {
      "rank": 1303,
      "cve_id": "CVE-2026-73974",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-22",
      "title": "linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73974"
    },
    {
      "rank": 1304,
      "cve_id": "CVE-2026-74967",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Same-origin policy bypass in the Audio/Video: Playback component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74967"
    },
    {
      "rank": 1305,
      "cve_id": "CVE-2026-45129",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-352",
      "title": "MyBB: ACP Recovery Codes CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45129"
    },
    {
      "rank": 1306,
      "cve_id": "CVE-2026-74980",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Clickjacking issue in the Downloads component in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74980"
    },
    {
      "rank": 1307,
      "cve_id": "CVE-2026-70806",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle E-Business Tax",
      "cwe": null,
      "title": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle E-Business Tax executes to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle E-Business Tax. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70806"
    },
    {
      "rank": 1308,
      "cve_id": "CVE-2026-70914",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70914"
    },
    {
      "rank": 1309,
      "cve_id": "CVE-2026-66589",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kings Plugins",
      "product": "B2BKing",
      "cwe": "CWE-862",
      "title": "WordPress B2BKing plugin <= 5.2.30 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66589"
    },
    {
      "rank": 1310,
      "cve_id": "CVE-2026-70962",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70962"
    },
    {
      "rank": 1311,
      "cve_id": "CVE-2026-75485",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-532",
      "title": "Must-gather: must-gather: cluster proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75485"
    },
    {
      "rank": 1312,
      "cve_id": "CVE-2026-70667",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-367",
      "title": "Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for CVE-2026-55162)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70667"
    },
    {
      "rank": 1313,
      "cve_id": "CVE-2026-66783",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.0339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-20",
      "title": "Submariner-operator: submariner-operator: arbitrary image override enables privileged code execution on every node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66783"
    },
    {
      "rank": 1314,
      "cve_id": "CVE-2026-45126",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-352",
      "title": "MyBB: ACP Questions state CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45126"
    },
    {
      "rank": 1315,
      "cve_id": "CVE-2026-45127",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-352",
      "title": "MyBB: ACP Mass Mail draft resend CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45127"
    },
    {
      "rank": 1316,
      "cve_id": "CVE-2026-45128",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-352",
      "title": "MyBB: ACP Users View Manager default CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45128"
    },
    {
      "rank": 1317,
      "cve_id": "CVE-2026-60902",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60902"
    },
    {
      "rank": 1318,
      "cve_id": "CVE-2026-62449",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Work in Process",
      "cwe": null,
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62449"
    },
    {
      "rank": 1319,
      "cve_id": "CVE-2026-45119",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mybb",
      "product": "mybb",
      "cwe": "CWE-352",
      "title": "MyBB: ACP UTF-8 Conversion CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45119"
    },
    {
      "rank": 1320,
      "cve_id": "CVE-2026-24183",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Cumulus Linux GA",
      "cwe": "CWE-250",
      "title": "NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24183"
    },
    {
      "rank": 1321,
      "cve_id": "CVE-2026-70798",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Purchasing",
      "cwe": null,
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Purchasing executes to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70798"
    },
    {
      "rank": 1322,
      "cve_id": "CVE-2026-71116",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71116"
    },
    {
      "rank": 1323,
      "cve_id": "CVE-2026-71117",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71117"
    },
    {
      "rank": 1324,
      "cve_id": "CVE-2026-70705",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.0277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70705"
    },
    {
      "rank": 1325,
      "cve_id": "CVE-2026-70712",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70712"
    },
    {
      "rank": 1326,
      "cve_id": "CVE-2026-71119",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71119"
    },
    {
      "rank": 1327,
      "cve_id": "CVE-2026-32657",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "AppSync",
      "cwe": "CWE-61",
      "title": "Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32657"
    },
    {
      "rank": 1328,
      "cve_id": "CVE-2026-55165",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.0269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-347",
      "title": "Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55165"
    },
    {
      "rank": 1329,
      "cve_id": "CVE-2026-62584",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62584"
    },
    {
      "rank": 1330,
      "cve_id": "CVE-2026-70916",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70916"
    },
    {
      "rank": 1331,
      "cve_id": "CVE-2026-70932",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Order Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70932"
    },
    {
      "rank": 1332,
      "cve_id": "CVE-2026-70902",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70902"
    },
    {
      "rank": 1333,
      "cve_id": "CVE-2026-62558",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62558"
    },
    {
      "rank": 1334,
      "cve_id": "CVE-2026-71132",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71132"
    },
    {
      "rank": 1335,
      "cve_id": "CVE-2026-70685",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 7.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70685"
    },
    {
      "rank": 1336,
      "cve_id": "CVE-2026-74963",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Same-origin policy bypass in the Networking: Cookies component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74963"
    },
    {
      "rank": 1337,
      "cve_id": "CVE-2026-50126",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KNMI",
      "product": "adaguc-server",
      "cwe": "CWE-125",
      "title": "adaguc-server GeoJSON coordinate parser (CConvertGeoJSON.cpp) vulnerable to out-of-bounds read and NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50126"
    },
    {
      "rank": 1338,
      "cve_id": "CVE-2026-70711",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70711"
    },
    {
      "rank": 1339,
      "cve_id": "CVE-2026-70919",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 2.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70919"
    },
    {
      "rank": 1340,
      "cve_id": "CVE-2026-71129",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71129"
    },
    {
      "rank": 1341,
      "cve_id": "CVE-2026-62570",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00123,
      "epss_percentile": 0.02504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62570"
    },
    {
      "rank": 1342,
      "cve_id": "CVE-2026-62583",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00123,
      "epss_percentile": 0.02504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62583"
    },
    {
      "rank": 1343,
      "cve_id": "CVE-2026-70879",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Data Relationship Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70879"
    },
    {
      "rank": 1344,
      "cve_id": "CVE-2026-71126",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71126"
    },
    {
      "rank": 1345,
      "cve_id": "CVE-2026-70992",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70992"
    },
    {
      "rank": 1346,
      "cve_id": "CVE-2026-71041",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71041"
    },
    {
      "rank": 1347,
      "cve_id": "CVE-2026-70841",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70841"
    },
    {
      "rank": 1348,
      "cve_id": "CVE-2026-75857",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-269",
      "title": "CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75857"
    },
    {
      "rank": 1349,
      "cve_id": "CVE-2026-60873",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60873"
    },
    {
      "rank": 1350,
      "cve_id": "CVE-2026-71013",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71013"
    },
    {
      "rank": 1351,
      "cve_id": "CVE-2026-60808",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": null,
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Marketing executes to compromise Siebel Apps - Marketing. While the vulnerability is in Siebel Apps - Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Marketing accessible data as well as unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60808"
    },
    {
      "rank": 1352,
      "cve_id": "CVE-2026-70758",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70758"
    },
    {
      "rank": 1353,
      "cve_id": "CVE-2026-70784",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70784"
    },
    {
      "rank": 1354,
      "cve_id": "CVE-2026-75904",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Konstanty Bialkowski",
      "product": "libmodplug",
      "cwe": "CWE-125",
      "title": "libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75904"
    },
    {
      "rank": 1355,
      "cve_id": "CVE-2026-70714",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Calculation Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 4.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70714"
    },
    {
      "rank": 1356,
      "cve_id": "CVE-2026-71144",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.02052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71144"
    },
    {
      "rank": 1357,
      "cve_id": "CVE-2026-71081",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.0205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71081"
    },
    {
      "rank": 1358,
      "cve_id": "CVE-2026-71046",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71046"
    },
    {
      "rank": 1359,
      "cve_id": "CVE-2026-61300",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": null,
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61300"
    },
    {
      "rank": 1360,
      "cve_id": "CVE-2026-62581",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62581"
    },
    {
      "rank": 1361,
      "cve_id": "CVE-2026-71101",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (US)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Tax Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71101"
    },
    {
      "rank": 1362,
      "cve_id": "CVE-2026-62573",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62573"
    },
    {
      "rank": 1363,
      "cve_id": "CVE-2026-71146",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.02003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 1.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71146"
    },
    {
      "rank": 1364,
      "cve_id": "CVE-2026-61298",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": null,
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61298"
    },
    {
      "rank": 1365,
      "cve_id": "CVE-2026-71151",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71151"
    },
    {
      "rank": 1366,
      "cve_id": "CVE-2026-70912",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70912"
    },
    {
      "rank": 1367,
      "cve_id": "CVE-2026-61339",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.0185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": null,
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61339"
    },
    {
      "rank": 1368,
      "cve_id": "CVE-2026-62536",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62536"
    },
    {
      "rank": 1369,
      "cve_id": "CVE-2026-71066",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 4.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71066"
    },
    {
      "rank": 1370,
      "cve_id": "CVE-2026-71083",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00116,
      "epss_percentile": 0.01877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71083"
    },
    {
      "rank": 1371,
      "cve_id": "CVE-2026-57826",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00115,
      "epss_percentile": 0.018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-295",
      "title": "An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate CAs are only verified for v3 certificates, and v1/v2 certificates are ignored.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57826"
    },
    {
      "rank": 1372,
      "cve_id": "CVE-2026-71094",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71094"
    },
    {
      "rank": 1373,
      "cve_id": "CVE-2026-71127",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": null,
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71127"
    },
    {
      "rank": 1374,
      "cve_id": "CVE-2026-71137",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71137"
    },
    {
      "rank": 1375,
      "cve_id": "CVE-2026-71033",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
      "cwe": null,
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71033"
    },
    {
      "rank": 1376,
      "cve_id": "CVE-2026-74968",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Site isolation issue in the Graphics: WebRender component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74968"
    },
    {
      "rank": 1377,
      "cve_id": "CVE-2026-71082",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71082"
    },
    {
      "rank": 1378,
      "cve_id": "CVE-2026-59781",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zabbix",
      "product": "Zabbix",
      "cwe": "CWE-427",
      "title": "Improper validation of custom installation directories on Windows could allow installation into locations with unsafe permissions, increasing the risk of DLL sideloading.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59781"
    },
    {
      "rank": 1379,
      "cve_id": "CVE-2026-71140",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71140"
    },
    {
      "rank": 1380,
      "cve_id": "CVE-2026-71154",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Helidon",
      "cwe": null,
      "title": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71154"
    },
    {
      "rank": 1381,
      "cve_id": "CVE-2026-18751",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Citrix",
      "product": "WorkSpace App",
      "cwe": "CWE-73",
      "title": "Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18751"
    },
    {
      "rank": 1382,
      "cve_id": "CVE-2026-70731",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Autonomous Health Framework",
      "cwe": null,
      "title": "Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 8.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70731"
    },
    {
      "rank": 1383,
      "cve_id": "CVE-2026-70693",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70693"
    },
    {
      "rank": 1384,
      "cve_id": "CVE-2026-62577",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00108,
      "epss_percentile": 0.01395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62577"
    },
    {
      "rank": 1385,
      "cve_id": "CVE-2026-60975",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": null,
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60975"
    },
    {
      "rank": 1386,
      "cve_id": "CVE-2026-61407",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Watchdog Timer Driver",
      "cwe": "CWE-698",
      "title": "Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61407"
    },
    {
      "rank": 1387,
      "cve_id": "CVE-2026-70796",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle General Ledger",
      "cwe": null,
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle General Ledger executes to compromise Oracle General Ledger. While the vulnerability is in Oracle General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70796"
    },
    {
      "rank": 1388,
      "cve_id": "CVE-2026-71078",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71078"
    },
    {
      "rank": 1389,
      "cve_id": "CVE-2026-71149",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71149"
    },
    {
      "rank": 1390,
      "cve_id": "CVE-2026-71072",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM MCAD Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71072"
    },
    {
      "rank": 1391,
      "cve_id": "CVE-2026-71477",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jdx",
      "product": "mise",
      "cwe": "CWE-278",
      "title": "mise: Incorrect file ownership, when installed by the root user using `install.sh`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71477"
    },
    {
      "rank": 1392,
      "cve_id": "CVE-2026-70850",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00101,
      "epss_percentile": 0.01038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70850"
    },
    {
      "rank": 1393,
      "cve_id": "CVE-2026-70697",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile Engineering Data Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70697"
    },
    {
      "rank": 1394,
      "cve_id": "CVE-2026-71098",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Business Intelligence Enterprise Edition",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71098"
    },
    {
      "rank": 1395,
      "cve_id": "CVE-2026-62575",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62575"
    },
    {
      "rank": 1396,
      "cve_id": "CVE-2026-71092",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise FIN Lease Administration",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease Administration executes to compromise PeopleSoft Enterprise FIN Lease Administration. While the vulnerability is in PeopleSoft Enterprise FIN Lease Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Lease Administration accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Lease Administration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71092"
    },
    {
      "rank": 1397,
      "cve_id": "CVE-2026-59915",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Alienware Command Center (AWCC)",
      "cwe": "CWE-272",
      "title": "Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59915"
    },
    {
      "rank": 1398,
      "cve_id": "CVE-2026-62511",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00097,
      "epss_percentile": 0.00864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Infrastructure Technology",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62511"
    },
    {
      "rank": 1399,
      "cve_id": "CVE-2026-60994",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Identity Manager Connector",
      "cwe": null,
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60994"
    },
    {
      "rank": 1400,
      "cve_id": "CVE-2026-70794",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Reporting",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70794"
    },
    {
      "rank": 1401,
      "cve_id": "CVE-2026-71105",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hyperion Financial Management",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 4.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71105"
    },
    {
      "rank": 1402,
      "cve_id": "CVE-2026-66782",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00083,
      "epss_percentile": 0.00287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-312",
      "title": "Submariner-operator: submariner-operator: broker api bearer token stored cleartext in cr spec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66782"
    },
    {
      "rank": 1403,
      "cve_id": "CVE-2026-71417",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00082,
      "epss_percentile": 0.00272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-639",
      "title": "Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71417"
    },
    {
      "rank": 1404,
      "cve_id": "CVE-2026-66781",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.0024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-312",
      "title": "Submariner-operator: submariner-operator: ipsec psk stored cleartext in submariner cr spec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66781"
    },
    {
      "rank": 1405,
      "cve_id": "CVE-2026-71317",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.0022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netflix",
      "product": "lemur",
      "cwe": "CWE-862",
      "title": "Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71317"
    },
    {
      "rank": 1406,
      "cve_id": "CVE-2026-49500",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Alienware Command Center (AWCC",
      "cwe": "CWE-272",
      "title": "Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service and Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49500"
    },
    {
      "rank": 1407,
      "cve_id": "CVE-2026-73834",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-312",
      "title": "Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redaction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73834"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-33824",
      "detail": "ADDED TO KEV — CVE-2026-33824 (Microsoft Windows 10 Version 1607). Remediation due August 21, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-55040",
      "detail": "ADDED TO KEV — CVE-2026-55040 (Microsoft SharePoint Enterprise Server 2016). Remediation due August 21, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-59310",
      "detail": "ADDED TO KEV — CVE-2026-59310 (VMware Cloud Foundation). Remediation due August 21, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-65400",
      "detail": "ADDED TO KEV — CVE-2026-65400 (Apple macOS). Remediation due August 21, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-14045",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-14045 (OpenBoxes). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-14046",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-14046 (OpenBoxes). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-21626",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-25256",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-25256 (Fortinet FortiSIEM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62593",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62593 (ray-project ray). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17106",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17106 (moby go-archive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19751",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19751 (EnzoVezzaro mcp-dominican-layer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19756",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19756 (Dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19758",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19758 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19765 (eyaushev swagger-testcase-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19771",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19771 (Baicells EG3661M). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19788",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19788 (Tenda AC1206). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19790",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19790 (Tenda G0). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19811",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19811 (TOTOLINK A800R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19813",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19813 (TOTOLINK A800R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19821",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19821 (Tenda AC12). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19823",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19823 (Tenda W20E). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19826",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19826 (alldatacenter alldata). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19828 (648540858 wvp-GB28181-pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19834",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19834 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19836",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19836 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19839",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19839 (SourceCodester Simple Doctors Appointment System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19844",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19844 (TOTOLINK A800R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19847",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19847 (TOTOLINK A800R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19894",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19894 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19896 (mangroup dtale). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19898",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19898 (VictoriaMetrics). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19899 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19901",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19901 (LB-LINK X-PRO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19904",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19904 (SourceCodester Online Book Store System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19905",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19905 (Jinher OA). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19916",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19916 (code-projects Online Food Order System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19918",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19918 (SpaceX Starlink Router Gen 3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19919",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19919 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19921",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19921 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19923",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19923 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19924",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19924 (Tenda AC10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19926",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19926 (Evergreen). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19928",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19928 (OpenBoxes). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19929",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19929 (OpenBoxes). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19932",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19932 (DefaultFuction Notice-System-Managent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19934",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19934 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19955",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19955 (TrailDB). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19957",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19957 (graphlit-mcp-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19959",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19959 (Edimax EW-7478APC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19960",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19960 (Edimax EW-7478APC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19962",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19962 (Edimax EW-7478APC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19964",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19964 (Jij-Inc Jij-MCP-Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19967",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19967 (Open Asset Import Library Assimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19969",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19969 (Open Asset Import Library Assimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19972",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19972 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19974",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19977",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19984",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19988",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19993",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19993 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19996",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19996 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19998 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24737",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24737 (parallax jsPDF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25535",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25535 (parallax jsPDF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25755",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25755 (parallax jsPDF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53365",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53365 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-60113",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-60113 (NASA-AMMOS AIT-DSN). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64600",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64600 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67579 (ash-project ash). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69414",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70667",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70667 (Netflix lemur). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7246",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7246 (Pallets Click Click). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72741",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72741 (goodrain rainbond). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73482",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73482 (phplist3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75077",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75077 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75079",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75079 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75080",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75080 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75081",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75081 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75082",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75082 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75086",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75086 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75087",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75087 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75088",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75088 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75089",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75089 (PHPGurukul Complaint Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75090",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75090 (EricLBuehler Mistral.rs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75093",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75093 (sonos tract). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75094",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75094 (COMFAST CF-N1-S). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75130",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75130 (Uptash Context7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75773",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75773 (karakeep-app karakeep). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75774 (karakeep-app karakeep). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75778",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75778 (code-projects Task Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75783",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75783 (TRENDnet TEW-WLC100P). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75784",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75784 (TRENDnet TEW-WLC100). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75876",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75876 (xianrendzw EasyReport). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75877",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75877 (TRENDnet TV-IP751WIC). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-44004",
      "detail": "RESCORED — CVE-2024-44004 (Arni Cinco WPCargo Track & Trace). CVSS 9.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-25755",
      "detail": "RESCORED — CVE-2026-25755 (parallax jsPDF). CVSS 8.1 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-31898",
      "detail": "RESCORED — CVE-2026-31898 (parallax jsPDF). CVSS 8.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-31938",
      "detail": "RESCORED — CVE-2026-31938 (parallax jsPDF). CVSS 9.6 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-40478",
      "detail": "RESCORED — CVE-2026-40478 (thymeleaf). CVSS 9.1 → 9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-41245",
      "detail": "RESCORED — CVE-2026-41245 (junrar). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75079",
      "detail": "RESCORED — CVE-2026-75079 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75080",
      "detail": "RESCORED — CVE-2026-75080 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75081",
      "detail": "RESCORED — CVE-2026-75081 (Webkul Bagisto). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-64158",
      "detail": "REJECTED — CVE-2026-64158 (Linux). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-73682",
      "detail": "REJECTED — CVE-2026-73682 (semaphoreui semaphore). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-74511",
      "detail": "REJECTED — CVE-2026-74511 (Linux). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18739",
      "detail": "PATCH SHIPPED — CVE-2026-18739 (rpm-software-management popt). Fixed in Red Hat Hardened Images 1.19-11.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-42965",
      "detail": "PATCH SHIPPED — CVE-2026-42965 (Red Hat OpenShift Container Platform 4.20). Fixed in Red Hat OpenShift Container Platform 4.20 1786496552."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-50236",
      "detail": "PATCH SHIPPED — CVE-2026-50236 (Red Hat OpenShift Container Platform 4.20). Fixed in Red Hat OpenShift Container Platform 4.20 1786534931."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-50237",
      "detail": "PATCH SHIPPED — CVE-2026-50237 (Red Hat OpenShift Container Platform 4.20). Fixed in Red Hat OpenShift Container Platform 4.20 1786534931."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-64611",
      "detail": "PATCH SHIPPED — CVE-2026-64611 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-64612",
      "detail": "PATCH SHIPPED — CVE-2026-64612 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66370",
      "detail": "PATCH SHIPPED — CVE-2026-66370 (rrrene html_sanitize_ex). Fixed in html_sanitize_ex a1e804ed997e780ea71d14393cf2f701330553a6."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66829",
      "detail": "PATCH SHIPPED — CVE-2026-66829 (rrrene html_sanitize_ex). Fixed in html_sanitize_ex 9f7e38be51edc38f132dfe994f37af5cf5e0e76f."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66843",
      "detail": "PATCH SHIPPED — CVE-2026-66843 (rrrene html_sanitize_ex). Fixed in html_sanitize_ex bec27fec4de99e40c68c4285a610e09e791a3eaf."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-68747",
      "detail": "PATCH SHIPPED — CVE-2026-68747 (rrrene html_sanitize_ex). Fixed in html_sanitize_ex 0b9f9ad63a7529d4f2c3c1134c371adc3e654308."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-68749",
      "detail": "PATCH SHIPPED — CVE-2026-68749 (rrrene html_sanitize_ex). Fixed in html_sanitize_ex 4f4bd9eb254881462c0461fbab74b29188c2c133."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-68750",
      "detail": "PATCH SHIPPED — CVE-2026-68750 (rrrene html_sanitize_ex). Fixed in html_sanitize_ex 9f5ccedbed230930813f992a1e6906fcf485981e."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
