{
  "day": "2026-08-19",
  "boundary": "UTC calendar day",
  "published_count": 673,
  "by_severity": {
    "CRITICAL": 100,
    "HIGH": 283,
    "MEDIUM": 228,
    "LOW": 36
  },
  "kev_count": 2,
  "exploit_reference_count": 2,
  "awaiting_enrichment_count": 26,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-72530",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01827,
      "epss_percentile": 0.77168,
      "kev": true,
      "kev_due_at": "2026-09-03",
      "vendor": "TrueConf",
      "product": "TrueConf Server",
      "cwe": "CWE-94",
      "title": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72530"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-72529",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01554,
      "epss_percentile": 0.73236,
      "kev": true,
      "kev_due_at": "2026-08-23",
      "vendor": "TrueConf",
      "product": "TrueConf Server",
      "cwe": "CWE-306",
      "title": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72529"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-71961",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.03051,
      "epss_percentile": 0.86545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Cudy Technology Co., Ltd.",
      "product": "WR3000 2.0",
      "cwe": "CWE-78",
      "title": "Cudy WR3000 2.0 OS Command Injection via Mesh MQTT Command Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71961"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-54795",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02391,
      "epss_percentile": 0.82684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-78",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54795"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-54796",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02358,
      "epss_percentile": 0.82451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-78",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54796"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-75616",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01908,
      "epss_percentile": 0.78174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer C20 v6",
      "cwe": "CWE-78",
      "title": "Command Injection in Router Web Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75616"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2024-58376",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01671,
      "epss_percentile": 0.74987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-78",
      "title": "Renovate 37.158.0 before 37.199.0 Command Injection via helmv3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58376"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-76761",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01583,
      "epss_percentile": 0.73657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chenhg5",
      "product": "cc-connect",
      "cwe": "CWE-77",
      "title": "chenhg5 cc-connect Management API engine.go shellExecCommand os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76761"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-76591",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01318,
      "epss_percentile": 0.68617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-755AP",
      "cwe": "CWE-74",
      "title": "TRENDnet TEW-755AP ssi email.cgi log_email_server command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76591"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-75984",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01293,
      "epss_percentile": 0.68086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-823DRU",
      "cwe": "CWE-74",
      "title": "TRENDnet TEW-823DRU admin.cgi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75984"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-75985",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01293,
      "epss_percentile": 0.68086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "Router",
      "cwe": "CWE-74",
      "title": "TRENDnet Router ping.cgi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75985"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-23501",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01285,
      "epss_percentile": 0.67931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "RecoverPoint for Virtual Machines",
      "cwe": "CWE-78",
      "title": "Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23501"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-76582",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01282,
      "epss_percentile": 0.6786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-821DAP",
      "cwe": "CWE-74",
      "title": "TRENDnet TEW-821DAP ssi ping.cgi system command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76582"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-76583",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.62202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TV-IP751WIC",
      "cwe": "CWE-74",
      "title": "TRENDnet TV-IP751WIC alphapd set_time.cgi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76583"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-15068",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0105,
      "epss_percentile": 0.61669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15068"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-63722",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00985,
      "epss_percentile": 0.59701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ICEcoder",
      "product": "ICEcoder",
      "cwe": "CWE-306",
      "title": "ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63722"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-76850",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00983,
      "epss_percentile": 0.59642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-502",
      "title": "LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76850"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-45741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00873,
      "epss_percentile": 0.56171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gotenberg",
      "product": "gotenberg",
      "cwe": "CWE-184",
      "title": "Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45741"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-76832",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00844,
      "epss_percentile": 0.55198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Agno AGI",
      "product": "Agno",
      "cwe": "CWE-22",
      "title": "Agno PythonTools Path Traversal via joinpath file_name argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76832"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-76166",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00841,
      "epss_percentile": 0.55118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7",
      "cwe": "CWE-476",
      "title": "Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast datagram",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76166"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-76231",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00733,
      "epss_percentile": 0.51591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-77",
      "title": "Renovate 32.135.0 before 40.33.0 Command Injection via hermit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76231"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-76230",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0073,
      "epss_percentile": 0.51484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-77",
      "title": "Renovate 35.63.0 before 40.33.0 Command Injection via npm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76230"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-76232",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0073,
      "epss_percentile": 0.51484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-77",
      "title": "Renovate 31.51.0 before 40.33.0 Command Injection via helmv3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76232"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-53451",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00725,
      "epss_percentile": 0.51311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgoudelis",
      "product": "ground-station",
      "cwe": "CWE-22",
      "title": "Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53451"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-76229",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00722,
      "epss_percentile": 0.51196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-77",
      "title": "Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76229"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-76233",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00722,
      "epss_percentile": 0.51196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-77",
      "title": "Renovate 39.53.0 before 40.33.0 Command Injection via gleam manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76233"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-16865",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00717,
      "epss_percentile": 0.50998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16865"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-76228",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.007,
      "epss_percentile": 0.50386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-78",
      "title": "Renovate before 42.68.5 Remote Code Execution via Gradle Wrapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76228"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-19942",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00687,
      "epss_percentile": 0.49927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpfeedback",
      "product": "Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback",
      "cwe": "CWE-22",
      "title": "Atarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19942"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-52889",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00682,
      "epss_percentile": 0.49691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verbb",
      "product": "formie",
      "cwe": "CWE-1336",
      "title": "Formie: Server-Side Template Injection in Formie Hidden field defaults",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52889"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-76314",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00666,
      "epss_percentile": 0.4904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-94",
      "title": "Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76314"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-69550",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00651,
      "epss_percentile": 0.48446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows App for Mac",
      "cwe": "CWE-125",
      "title": "Windows App for Mac Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69550"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-32475",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00645,
      "epss_percentile": 0.48166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elementor",
      "product": "Elementor Pro",
      "cwe": "CWE-434",
      "title": "WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32475"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-16919",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00643,
      "epss_percentile": 0.48059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-843",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16919"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-48024",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0064,
      "epss_percentile": 0.47881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-22",
      "title": "Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48024"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-75149",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00637,
      "epss_percentile": 0.47773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marimo-team",
      "product": "marimo",
      "cwe": "CWE-94",
      "title": "marimo < 0.23.15 Code Injection via MCP Server Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75149"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-16894",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00616,
      "epss_percentile": 0.46783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16894"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-16913",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00616,
      "epss_percentile": 0.46784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16913"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-76589",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00614,
      "epss_percentile": 0.46706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-755AP",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76589"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-76590",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00614,
      "epss_percentile": 0.46705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-755AP",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-755AP ssi wan.cgi stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76590"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-16885",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00603,
      "epss_percentile": 0.46175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-121",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16885"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-16850",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00602,
      "epss_percentile": 0.46151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16850"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-16917",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00598,
      "epss_percentile": 0.45941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-190",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16917"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-18315",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00598,
      "epss_percentile": 0.45966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker – Appointment Booking and Scheduler System",
      "cwe": "CWE-639",
      "title": "TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18315"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-16840",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00585,
      "epss_percentile": 0.45352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16840"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-76224",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00583,
      "epss_percentile": 0.45219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-94",
      "title": "ArcadeDB before 26.8.1 Remote Code Execution via Groovy Fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76224"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-16911",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00578,
      "epss_percentile": 0.44968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-121",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16911"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-76008",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00574,
      "epss_percentile": 0.44772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfast",
      "product": "CF-N1-S",
      "cwe": "CWE-119",
      "title": "Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76008"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-76404",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00561,
      "epss_percentile": 0.44141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk MCP Server app",
      "cwe": "CWE-502",
      "title": "Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76404"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-49289",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.44049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simplesamlphp",
      "product": "saml2",
      "cwe": "CWE-400",
      "title": "SimpleSAMLphp SAML2: Possible DoS via XPath Transform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49289"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-16882",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00554,
      "epss_percentile": 0.43748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16882"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-20357",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0055,
      "epss_percentile": 0.43509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Crosswork Planning",
      "cwe": "CWE-306",
      "title": "Cisco Crosswork Security Hardening Release: August 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20357"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-20030",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00546,
      "epss_percentile": 0.43314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Crosswork Planning",
      "cwe": "CWE-89",
      "title": "Cisco Crosswork Security Hardening Release: August 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20030"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-72717",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00546,
      "epss_percentile": 0.43321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: Import-time RCE via schema default -> zod module-level template literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72717"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-71960",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00544,
      "epss_percentile": 0.43201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Cudy Technology Co., Ltd.",
      "product": "WR3000 2.0",
      "cwe": "CWE-798",
      "title": "Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71960"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-16616",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00543,
      "epss_percentile": 0.43171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple File List",
      "cwe": "CWE-22",
      "title": "Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16616"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-73136",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00543,
      "epss_percentile": 0.43168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-294",
      "title": "Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73136"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-75593",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0054,
      "epss_percentile": 0.43008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "buildkit",
      "cwe": "CWE-22",
      "title": "BuildKit: Malicious client can bypass destination directory validation on local sources upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75593"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-53545",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.42836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-78",
      "title": "Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53545"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-67189",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0053,
      "epss_percentile": 0.42393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netgate",
      "product": "pfSense Plus",
      "cwe": "CWE-79",
      "title": "pfSense Plus/CE Stored XSS via Traffic Graphs PTR Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67189"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-49255",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.4222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-78",
      "title": "electerm: Command Injection in File System Operations (rmrf, mv, cp)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49255"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-62681",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00523,
      "epss_percentile": 0.41969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62681"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-72716",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00523,
      "epss_percentile": 0.41969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-1336",
      "title": "Orval: Import-time RCE via query-parameter default -> zod module-level template literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72716"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-55087",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00523,
      "epss_percentile": 0.42015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ether",
      "product": "etherpad",
      "cwe": "CWE-79",
      "title": "Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55087"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-62317",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.41926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-1333",
      "title": "Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62317"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-45274",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00518,
      "epss_percentile": 0.41675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PoxenStudio",
      "product": "talebook",
      "cwe": "CWE-602",
      "title": "MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45274"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-48162",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0051,
      "epss_percentile": 0.41146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-73",
      "title": "Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48162"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-20231",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00502,
      "epss_percentile": 0.40613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Workload",
      "cwe": "CWE-74",
      "title": "Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20231"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-62682",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.005,
      "epss_percentile": 0.40508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62682"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-76313",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00499,
      "epss_percentile": 0.40466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Remote Code Execution (RCE) through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76313"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-67581",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00497,
      "epss_percentile": 0.40361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-294",
      "title": "On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67581"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-50173",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00497,
      "epss_percentile": 0.40353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rheosoph",
      "product": "flow-like",
      "cwe": "CWE-863",
      "title": "Flow-Like: Azure invoke presign grants app content write SAS to ExecuteEvents-only users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50173"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-45798",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00496,
      "epss_percentile": 0.40315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-121",
      "title": "Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45798"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-76584",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TV-IP751WIC",
      "cwe": "CWE-119",
      "title": "TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76584"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-76218",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00492,
      "epss_percentile": 0.40009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-88",
      "title": "GitPython before 3.1.58 Remote Code Execution via Repo.init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76218"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-45742",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0049,
      "epss_percentile": 0.3989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gotenberg",
      "product": "gotenberg",
      "cwe": "CWE-362",
      "title": "Gotenberg: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45742"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-16845",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00489,
      "epss_percentile": 0.39854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16845"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-16862",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00489,
      "epss_percentile": 0.39854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16862"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-53542",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.39846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-78",
      "title": "Termix: Tar option injection in file-manager archive creation allows command execution on managed SSH hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53542"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-55193",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.39867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP: Heap-buffer-overflow write in TS Gateway RPC fragment receive due to uncapped bind_ack max_xmit_frag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55193"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-76395",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.39683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-502",
      "title": "Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76395"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-16816",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.3964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16816"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2022-4996",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00485,
      "epss_percentile": 0.39532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "mruby",
      "cwe": "CWE-1077",
      "title": "mruby bigint.c udiv floating point comparison with incorrect operator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-4996"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-15065",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00482,
      "epss_percentile": 0.39358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-312",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15065"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-55191",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP: Heap-buffer-overflow write in AVC444 YUV buffer allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55191"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-66613",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.3909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-1336",
      "title": "WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66613"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-71864",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71864"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-71865",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71865"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-71866",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-89",
      "title": "Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71866"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-71867",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-89",
      "title": "Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71867"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-71868",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: Import-time RCE via enum-typed default -> zod module-level template literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71868"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-71869",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: Import-time RCE via array-items default -> zod module-level template literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71869"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-71871",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "Orval: Import-time RCE via header-parameter default -> zod module-level template literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71871"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-76878",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.38962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Aodh",
      "cwe": "CWE-688",
      "title": "In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76878"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-16877",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.38466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-121",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16877"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-16872",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00465,
      "epss_percentile": 0.38228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-121",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16872"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-76220",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-88",
      "title": "GitPython before 3.1.58 Command Execution via split_single_char_options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76220"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-76003",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76003"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-49441",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00461,
      "epss_percentile": 0.37953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-73",
      "title": "Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49441"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-55194",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.37808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55194"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-63633",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.37809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the wrong stream) — server→client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63633"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-16834",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00458,
      "epss_percentile": 0.37777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-190",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16834"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-20358",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.37701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Crosswork Planning",
      "cwe": "CWE-73",
      "title": "Cisco Crosswork Security Hardening Release: August 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20358"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-16864",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.37613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16864"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-76315",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00443,
      "epss_percentile": 0.36682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-94",
      "title": "Code Injection through Splunk Web Manager Configuration in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76315"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-20317",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.3651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Workload",
      "cwe": "CWE-287",
      "title": "Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20317"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-63188",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.3654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-22",
      "title": "logto-tunnel serves files outside --experience-path via path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63188"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-44255",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00439,
      "epss_percentile": 0.3637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-208",
      "title": "Wazuh: Username Enumeration via Timing Side-Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44255"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-18051",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "W3 Total Cache",
      "cwe": "CWE-22",
      "title": "W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18051"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-76004",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1250GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76004"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-54739",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00432,
      "epss_percentile": 0.3583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LemmyNet",
      "product": "lemmy",
      "cwe": "CWE-204",
      "title": "Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54739"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-68560",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.35626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-78",
      "title": "Wekan:hell Injection in External Antivirus Scanner Path via asyncExec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68560"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-15061",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00429,
      "epss_percentile": 0.35493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-22",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15061"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-52792",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-69",
      "title": "Algernon: Server-side script source disclosure on Windows via NTFS filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52792"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-53549",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-918",
      "title": "Termix: Server-Side Request Forgery via Proxy Connectivity Test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53549"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-54738",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.35414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LemmyNet",
      "product": "lemmy",
      "cwe": "CWE-799",
      "title": "Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54738"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-62666",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-api",
      "cwe": "CWE-639",
      "title": "Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62666"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-16656",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00423,
      "epss_percentile": 0.35076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-287",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16656"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-75987",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00423,
      "epss_percentile": 0.3507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPLWare",
      "product": "esProc",
      "cwe": "CWE-20",
      "title": "SPLWare esProc SocketData.java ObjectInputStream.readUnshared deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75987"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-73541",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.34673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-770",
      "title": "Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73541"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-54742",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.34684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LemmyNet",
      "product": "lemmy",
      "cwe": "CWE-863",
      "title": "Lemmy: `CollectionAdd::Featured` does not check the post is in the community",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54742"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-44253",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00417,
      "epss_percentile": 0.34427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-770",
      "title": "Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44253"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-20315",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Workload",
      "cwe": "CWE-284",
      "title": "Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20315"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-47187",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libfuse",
      "product": "sshfs",
      "cwe": "CWE-59",
      "title": "SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47187"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-55090",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ether",
      "product": "etherpad",
      "cwe": "CWE-79",
      "title": "Etherpad: Stored XSS in HTML export via unescaped attribute-pool values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55090"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-44901",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.33949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-502",
      "title": "Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44901"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-45273",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.33663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PoxenStudio",
      "product": "talebook",
      "cwe": "CWE-862",
      "title": "MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45273"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-75143",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-122",
      "title": "FFmpeg Heap Buffer Overflow via RIST Protocol Reader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75143"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-16824",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16824"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-16831",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16831"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-16836",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16836"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-61712",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00404,
      "epss_percentile": 0.3328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "buildkit",
      "cwe": "CWE-770",
      "title": "BuildKit: Possible runtime DoS via unbounded group parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61712"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-68899",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.3324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-434",
      "title": "Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68899"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-19490",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-288",
      "title": "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19490"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-62673",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.3308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-178",
      "title": "Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62673"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-54743",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.32961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LemmyNet",
      "product": "lemmy",
      "cwe": "CWE-79",
      "title": "Lemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54743"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-55648",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.32913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-190",
      "title": "FreeRDP: Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55648"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-76243",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.004,
      "epss_percentile": 0.32829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem",
      "cwe": "CWE-285",
      "title": "stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76243"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-53547",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.004,
      "epss_percentile": 0.32886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-862",
      "title": "Termix: Account Takeover via Global Settings Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53547"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-76345",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.004,
      "epss_percentile": 0.32907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Remote Code Execution (RCE) through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76345"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-16888",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.004,
      "epss_percentile": 0.32851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-22",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16888"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-55192",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.32679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-125",
      "title": "FreeRDP: Out-of-bounds read in H.264 YUV-to-RGB conversion due to decoder/surface dimension mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55192"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-75919",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.3255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-306",
      "title": "phpMyFAQ before 4.1.7 Authentication Bypass via Setup API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75919"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-18937",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00395,
      "epss_percentile": 0.3235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Broken Link Checker",
      "cwe": "CWE-94",
      "title": "Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18937"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-15780",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veronalabs",
      "product": "WP Statistics – Simple, privacy-friendly Google Analytics alternative",
      "cwe": "CWE-79",
      "title": "WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15780"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-63117",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.31691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-369",
      "title": "FreeRDP: Denial of service through ADPCM frame size calculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63117"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-20177",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.31722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Industrial Ethernet Switches",
      "cwe": "CWE-770",
      "title": "Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20177"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-19489",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.31591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-120",
      "title": "Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19489"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-76317",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-26",
      "title": "Path Traversal through the Lookup Configuration REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76317"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-16852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-190",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16852"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-62669",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-287",
      "title": "Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62669"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-53654",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-601",
      "title": "Grav: Unauthenticated open redirect via login twofa_cancel _redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53654"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-16839",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.31239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16839"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-20320",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco BroadWorks",
      "cwe": "CWE-611",
      "title": "A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface &ndash; Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20320"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-53452",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgoudelis",
      "product": "ground-station",
      "cwe": "CWE-22",
      "title": "Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53452"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-76319",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.30678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Remote Code Execution (RCE) through Federated Search in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76319"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2025-36254",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.30695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DS8A00 (R10.0 - R10.1)",
      "cwe": "CWE-116",
      "title": "DS8900F and DS8A00 Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36254"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-61690",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-409",
      "title": "Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61690"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-68901",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-476",
      "title": "WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68901"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-68561",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-269",
      "title": "Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow rule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68561"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2025-14600",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vsDesk",
      "product": "vsDesk",
      "cwe": "CWE-305",
      "title": "Admin Account Takeover via Path Traversal in vsDesk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14600"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-76221",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-74",
      "title": "GitPython before 3.1.58 Config Injection via option-name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76221"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-76262",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-200",
      "title": "Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76262"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-44829",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.29874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gotenberg",
      "product": "gotenberg",
      "cwe": "CWE-22",
      "title": "Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44829"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-76310",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.29684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76310"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-76311",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.29685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76311"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-45272",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.29371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PoxenStudio",
      "product": "talebook",
      "cwe": "CWE-94",
      "title": "MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45272"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-20319",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Workload",
      "cwe": "CWE-119",
      "title": "Cisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20319"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-18430",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HumHub",
      "product": "HumHub",
      "cwe": "CWE-79",
      "title": "HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18430"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-69222",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-400",
      "title": "LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69222"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-76576",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00365,
      "epss_percentile": 0.29203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yangzongzhuan",
      "product": "RuoYi-Vue",
      "cwe": "CWE-22",
      "title": "yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76576"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-53546",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.28935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-639",
      "title": "Termix: Missing authorization in SSH host credential resolution exposes stored credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53546"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-55085",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.2891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ether",
      "product": "etherpad",
      "cwe": "CWE-79",
      "title": "Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55085"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-76312",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.28918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Improper Access Control through Embedded Reports in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76312"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-76356",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.28885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-290",
      "title": "Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76356"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-14334",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.28763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking calendar, Appointment Booking System",
      "cwe": "CWE-79",
      "title": "Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14334"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-76358",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.28747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-22",
      "title": "Path Traversal through App Installation Tar Extraction in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76358"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-76359",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.28747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-22",
      "title": "Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76359"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-63408",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.28703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-api",
      "cwe": "CWE-598",
      "title": "Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63408"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-20359",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00359,
      "epss_percentile": 0.28517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Crosswork Planning",
      "cwe": "CWE-522",
      "title": "Cisco Crosswork Security Hardening Release: August 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20359"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-16857",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.28436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-287",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16857"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-19875",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.28467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-306",
      "title": "Unauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in Langflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19875"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-55088",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.2838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ether",
      "product": "etherpad",
      "cwe": "CWE-200",
      "title": "Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55088"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-61711",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "buildkit",
      "cwe": "CWE-20",
      "title": "BuildKit: Custom frontend could bypass Seccomp/AppArmor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61711"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-55089",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ether",
      "product": "etherpad",
      "cwe": "CWE-863",
      "title": "Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55089"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-53548",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.2815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-285",
      "title": "Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53548"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-76235",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-401",
      "title": "Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76235"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-44254",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-131",
      "title": "Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44254"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-76355",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.2809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-306",
      "title": "Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76355"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-54741",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.2809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LemmyNet",
      "product": "lemmy",
      "cwe": "CWE-862",
      "title": "Lemmy: Blocked users can edit private messages sent before the block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54741"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-75596",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.2766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-407",
      "title": "Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75596"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-76253",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.27605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-269",
      "title": "Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76253"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-76391",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-863",
      "title": "Improper Privilege Management through Agent Run History in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76391"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-20318",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Workload",
      "cwe": "CWE-20",
      "title": "Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20318"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-49283",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.26927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simplesamlphp",
      "product": "saml2",
      "cwe": "CWE-295",
      "title": "SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49283"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-18544",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.26904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Portieris",
      "cwe": "CWE-862",
      "title": "Portieris is vulnerable to Image Policy Bypass via Unvalidated ownerReference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18544"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-64850",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.26782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64850"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-18756",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.26781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HumHub",
      "product": "HumHub",
      "cwe": "CWE-79",
      "title": "HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18756"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-32552",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITH",
      "product": "YITH WooCommerce Membership Premium",
      "cwe": "CWE-89",
      "title": "WordPress YITH WooCommerce Membership Premium plugin <= 2.33.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32552"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-63652",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-415",
      "title": "FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Client Audio Formats PDU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63652"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-76164",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail-project",
      "product": "ail-framework",
      "cwe": "CWE-918",
      "title": "Authenticated Server-Side Request Forgery in AIL Framework Crawler Allows Access to Internal Network Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76164"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-18031",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00341,
      "epss_percentile": 0.26671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TabaPay Gateway",
      "cwe": "CWE-287",
      "title": "TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18031"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-18776",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00341,
      "epss_percentile": 0.26673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TrueBooker",
      "cwe": "CWE-284",
      "title": "TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18776"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-16617",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.26499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple File List",
      "cwe": "CWE-79",
      "title": "Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16617"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-76389",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Cisco Talos Intelligence for Enterprise Security Cloud",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76389"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-64851",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-shortcode-core",
      "cwe": "CWE-79",
      "title": "Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64851"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-18526",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HumHub",
      "product": "HumHub",
      "cwe": "CWE-79",
      "title": "HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18526"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-76321",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-77",
      "title": "SPL Injection through Nearby Event Searches in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76321"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-49976",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: User Account Escalation via CSV Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49976"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-41424",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-863",
      "title": "Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41424"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-49253",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.25979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-22",
      "title": "electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49253"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-70424",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.25991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-22",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70424"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-76572",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.25905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pkp",
      "product": "pkp-lib",
      "cwe": "CWE-610",
      "title": "pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76572"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-76335",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.25807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-94",
      "title": "Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76335"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-70408",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.25657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extra Innovation Inc.",
      "product": "acmailer CGI",
      "cwe": "CWE-863",
      "title": "An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70408"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-62668",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.25289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-918",
      "title": "Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62668"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-65612",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nnn",
      "product": "nnn",
      "cwe": "CWE-78",
      "title": "Shell Command Injection in nnn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65612"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-76760",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chenhg5",
      "product": "cc-connect",
      "cwe": "CWE-74",
      "title": "chenhg5 cc-connect webhook.go authenticate code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76760"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-66794",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-918",
      "title": "Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66794"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-76139",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-829",
      "title": "Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76139"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-75986",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Job Portal System",
      "cwe": "CWE-74",
      "title": "code-projects Online Job Portal System Password Recovery ForPass.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75986"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-76048",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76048"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-76049",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.2515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php save_menu sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76049"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-76050",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php delete_menu sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76050"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-76574",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hospital Information System",
      "cwe": "CWE-74",
      "title": "code-projects Hospital Information System User Login UsersController.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76574"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-16827",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-908",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16827"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-76357",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.24865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-22",
      "title": "Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76357"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-71470",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-913",
      "title": "Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71470"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-12983",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dinatur",
      "cwe": "CWE-89",
      "title": "Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12983"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-16950",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Shortlist",
      "cwe": "CWE-89",
      "title": "Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16950"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-19672",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.24689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": null,
      "title": "tarfile extraction filter bypass allows creation of directories outside the destination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19672"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-65611",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.24599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nnn",
      "product": "nnn",
      "cwe": "CWE-78",
      "title": "Shell Command Injection in nnn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65611"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-16019",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Faydam Innovation Inc.",
      "product": "FAYDAM Datalogger",
      "cwe": "CWE-89",
      "title": "SQL Injection in Faydam Innovation's FAYDAM Datalogger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16019"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-61842",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.24297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-200",
      "title": "Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61842"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-73389",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0032,
      "epss_percentile": 0.24203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The4",
      "product": "Kalles Addons",
      "cwe": "CWE-502",
      "title": "WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73389"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-75955",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.2396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75955"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-75595",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00317,
      "epss_percentile": 0.23931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-754",
      "title": "Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75595"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-76886",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.23846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76886"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-67363",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.23937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms extension for Joomla",
      "cwe": "CWE-472",
      "title": "Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67363"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-13174",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.23821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-284",
      "title": "Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13174"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-70421",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.23822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-269",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70421"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-61556",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.23635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-835",
      "title": "LiquidJS: An infinite loop vulnerability in `strip_html` filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61556"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-68552",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.23669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-190",
      "title": "Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68552"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-71176",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-89",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71176"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2019-25766",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-532",
      "title": "Renovate before 19.38.7 Credential Exposure via Go Modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25766"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2020-37267",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-532",
      "title": "Renovate 19.180.0 before 23.25.1 Token Leakage via Logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37267"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-44252",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-863",
      "title": "Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44252"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-16690",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16690"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-16706",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16706"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-16818",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.2354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16818"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-73364",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.23505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdesk",
      "product": "Flexible Subscriptions",
      "cwe": "CWE-502",
      "title": "WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73364"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-16817",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.23502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-476",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16817"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-49870",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.23439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-770",
      "title": "Snipe-IT: TOTP Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49870"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-74803",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.23293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74803"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-75949",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.23296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75949"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-61518",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ispconfig",
      "product": "ispconfig3",
      "cwe": "CWE-89",
      "title": "ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61518"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-75956",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-770",
      "title": "Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75956"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-54740",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LemmyNet",
      "product": "lemmy",
      "cwe": "CWE-862",
      "title": "Lemmy: Lower-ranked federated moderator can remove higher-ranked moderators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54740"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-16842",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.22965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16842"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-16844",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.22966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16844"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-16848",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.22966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16848"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-14861",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Verification by PickPlugins",
      "cwe": "CWE-639",
      "title": "User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14861"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-62680",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-22",
      "title": "Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62680"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-68555",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.2294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-400",
      "title": "coturn: Chained mobility resumes allow authenticated remote memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68555"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-18372",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M-Files Corporation",
      "product": "M-Files Web",
      "cwe": "CWE-79",
      "title": "CSS injection in M-Files Web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18372"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-19508",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00309,
      "epss_percentile": 0.22981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RDK",
      "product": "RDK-B WebUI",
      "cwe": null,
      "title": "RDK WebUI heap-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19508"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-76254",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.22935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-943",
      "title": "SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76254"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-17015",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.22933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17015"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-76365",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.22616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-74",
      "title": "Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76365"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-16833",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.22649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16833"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-75979",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00305,
      "epss_percentile": 0.22574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xianrendzw",
      "product": "EasyReport",
      "cwe": "CWE-791",
      "title": "xianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText special elements in template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75979"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-76372",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.22499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Nmap Scanner",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment through Safe Mode in Nmap Scanner for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76372"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-64852",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-api",
      "cwe": "CWE-862",
      "title": "Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64852"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-18874",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-94",
      "title": "Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscription",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18874"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-55483",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-862",
      "title": "Snipe-IT: Privilege Escalation via Missing admin Permission Check in User Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55483"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-56088",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-89",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56088"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-70422",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-89",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70422"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-76316",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-943",
      "title": "Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76316"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-62672",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-1333",
      "title": "Grav: Authenticated ReDoS via regex_replace in Twig Sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62672"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-76337",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-22",
      "title": "Path Traversal through Splunk Web Static File Serving in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76337"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-76402",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.21926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Connect for Kafka",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76402"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-76212",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.21868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-88",
      "title": "phpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76212"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-15421",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.21886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siteground",
      "product": "Speed Optimizer – The All-In-One Performance-Boosting Plugin",
      "cwe": "CWE-79",
      "title": "Speed Optimizer <= 7.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15421"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-63187",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.21887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-94",
      "title": "Logto: OS command injection vulnerability exists in the Commitlint workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63187"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-68558",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.21705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-918",
      "title": "Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68558"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-76344",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.21557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-27",
      "title": "Path Traversal through the Search Dispatch REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76344"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-75950",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.21508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75950"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-75951",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.2151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75951"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-75114",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.21509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-601",
      "title": "Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75114"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-67364",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.21319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67364"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-62667",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-api",
      "cwe": "CWE-862",
      "title": "Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62667"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-68559",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-639",
      "title": "Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68559"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-16686",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-287",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16686"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-76366",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-200",
      "title": "Information Disclosure through the REST API in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76366"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-76214",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-294",
      "title": "phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76214"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-71694",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00292,
      "epss_percentile": 0.21146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, CSRFile logic in ProcessorFuzz BOOM benchmark Benchmarks/Verilog/SmallBoomTile_v1.2_state.v",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71694"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-16841",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16841"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-76390",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Cisco Talos Intelligence for Enterprise Security Cloud",
      "cwe": "CWE-200",
      "title": "Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76390"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-51366",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00291,
      "epss_percentile": 0.21053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51366"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-76237",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.20913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem-node",
      "cwe": "CWE-639",
      "title": "stigmem before 0.9.0a12 Cross-Tenant BOLA via quarantine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76237"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-49428",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.2098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-915",
      "title": "posixshm: system calls can incorrectly free memory of largepage objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49428"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-15253",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.20975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Media Replace",
      "cwe": "CWE-79",
      "title": "Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15253"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-18202",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.20975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18202"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-76322",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.20854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "SPL Injection through Dashboard Studio Search Query Options in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76322"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-76363",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.20884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-943",
      "title": "Structured Query Language Injection through the REST API in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76363"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-76203",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.20856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maalfer",
      "product": "Pentestify",
      "cwe": "CWE-180",
      "title": "CSS sanitizer bypass in Pentestify report themes allows forced outbound requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76203"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-18371",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.20798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M-Files Corporation",
      "product": "M-Files Web",
      "cwe": "CWE-79",
      "title": "HTML injection in M-Files Web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18371"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-76222",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.20648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-22",
      "title": "GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76222"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-13175",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-639",
      "title": "Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13175"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-44256",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.20629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-117",
      "title": "Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44256"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-16903",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00286,
      "epss_percentile": 0.20575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16903"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-16901",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16901"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-16909",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-128",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16909"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-49419",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-911",
      "title": "Jail reference count underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49419"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-75569",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-829",
      "title": "Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mutable stolostron/release@master",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75569"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-76210",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-73",
      "title": "phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76210"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-76928",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.20397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76928"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-17183",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.20403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-863",
      "title": "CVE-2026-17183 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17183"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-76364",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.20415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-89",
      "title": "Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76364"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-76400",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.20421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Connect for Kafka",
      "cwe": "CWE-400",
      "title": "Denial of Service (DoS) through the REST API in Splunk Connect for Kafka",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76400"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-76401",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.20422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Connect for Kafka",
      "cwe": "CWE-407",
      "title": "Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for Kafka",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76401"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-61807",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT: Stored DOM XSS via table selected-count IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61807"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-76353",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-24",
      "title": "Path Traversal through Knowledge Bundle Replication in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76353"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-76350",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-269",
      "title": "Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76350"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-73387",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SmartDataSoft",
      "product": "Resido",
      "cwe": "CWE-98",
      "title": "WordPress Resido theme <= 1.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73387"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-74804",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.19993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74804"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-75954",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.19993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75954"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2025-14603",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.19993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vsDesk",
      "product": "vsDesk",
      "cwe": null,
      "title": "Use of user input in raw SQL queries in vsDesk leading to blind SQL injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14603"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-8619",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR100 v3.2",
      "cwe": "CWE-476",
      "title": "Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8619"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-76217",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-73",
      "title": "GitPython before 3.1.58 Arbitrary File Read via pathspec-from-file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76217"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-76213",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0028,
      "epss_percentile": 0.19891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-307",
      "title": "phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76213"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-49418",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.19878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Use-after-free in device pager page list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49418"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-76240",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.19828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem",
      "cwe": "CWE-89",
      "title": "stigmem Postgres SQL Injection via Schema Identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76240"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-76879",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.19791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76879"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-76880",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.19791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76880"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-68553",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.19822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-134",
      "title": "Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68553"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-59992",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.19779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinacms",
      "product": "tinacms",
      "cwe": "CWE-639",
      "title": "Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59992"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-66668",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.19637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PeepSo",
      "product": "Community by PeepSo",
      "cwe": "CWE-89",
      "title": "WordPress Community by PeepSo plugin <= 9.0.5.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66668"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-76387",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.19661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise Security",
      "cwe": "CWE-20",
      "title": "SPL Injection through the REST API in Splunk Enterprise Security",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76387"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-76219",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.19555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-88",
      "title": "GitPython before 3.1.58 Arbitrary File Overwrite via read-tree",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76219"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-70423",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.19601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-611",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70423"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-20314",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.19569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Packaged Contact Center Enterprise",
      "cwe": "CWE-918",
      "title": "Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20314"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-76343",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.19506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-89",
      "title": "Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76343"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-75978",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00276,
      "epss_percentile": 0.19405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xianrendzw",
      "product": "EasyReport",
      "cwe": "CWE-266",
      "title": "xianrendzw EasyReport QueryerFactory DataSourceController.java DataSourceController.add permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75978"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-76338",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-287",
      "title": "Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76338"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-76762",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Assessment Management",
      "cwe": "CWE-74",
      "title": "code-projects Assessment Management welcome.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76762"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-73390",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KlbTheme",
      "product": "Total Donations",
      "cwe": "CWE-266",
      "title": "WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73390"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-49420",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-121",
      "title": "Buffer overflow in libalias RTSP handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49420"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-76614",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-22",
      "title": "OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76614"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-49427",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-826",
      "title": "posixshm: largepage shared memory objects not explicitly wired",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49427"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-54494",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koel",
      "product": "koel",
      "cwe": "CWE-918",
      "title": "Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54494"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-16847",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.18777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16847"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-63407",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.18762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-api",
      "cwe": "CWE-942",
      "title": "Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63407"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-76340",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.18668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76340"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-76207",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.18542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-304",
      "title": "phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76207"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-16866",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.18535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16866"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-73347",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.18477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemetechMount",
      "product": "TrueBooker",
      "cwe": "CWE-266",
      "title": "WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73347"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-76242",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00267,
      "epss_percentile": 0.18361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem",
      "cwe": "CWE-295",
      "title": "stigmem Federation Peer Registration Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76242"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-14970",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-120",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14970"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-16837",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16837"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-55564",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-125",
      "title": "FreeRDP: Out-of-bounds read in glyph_cache_get via crafted glyph fragments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55564"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-76236",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.17969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem-node",
      "cwe": "CWE-639",
      "title": "stigmem before 0.9.0a12 Cross-Tenant BOLA via Tombstones",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76236"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-76238",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.17969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem-node",
      "cwe": "CWE-863",
      "title": "stigmem before 0.9.0a12 Cross-Tenant BOLA via decay sweep",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76238"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-76239",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.17964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem-node",
      "cwe": "CWE-918",
      "title": "Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76239"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-54492",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.17955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koel",
      "product": "koel",
      "cwe": "CWE-918",
      "title": "Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54492"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-54493",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.17769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koel",
      "product": "koel",
      "cwe": "CWE-918",
      "title": "Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54493"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-76216",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.17817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-639",
      "title": "Vikunja through 2.4.0 Principal-Type Confusion via LinkSharing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76216"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-46343",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.17883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-22",
      "title": "Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46343"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-76369",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.17644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-22",
      "title": "Path Traversal through Automation Broker in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76369"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-75146",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-125",
      "title": "FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75146"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-76206",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-200",
      "title": "phpMyFAQ before 4.1.7 Information Disclosure via PDF Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76206"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-75920",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-377",
      "title": "phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75920"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-55643",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55643"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-76260",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment for Critical Resource through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76260"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-16825",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16825"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-70496",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-250",
      "title": "Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70496"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-76225",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-918",
      "title": "ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76225"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-76394",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.1706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76394"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-76333",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76333"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-19709",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.16988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Membership For WooCommerce",
      "cwe": "CWE-287",
      "title": "Membership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19709"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-76208",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.16569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-778",
      "title": "phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76208"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-76352",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.16608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-285",
      "title": "Improper Authorization through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76352"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-76397",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-639",
      "title": "Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76397"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-75918",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-200",
      "title": "phpMyFAQ before 4.1.7 Authentication Bypass via Tracking File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75918"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-68900",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-79",
      "title": "Wekan: Stored XSS in HTML board exports through a card-title second parse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68900"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2025-36255",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.1634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DS8A00( R10.0 - R10.1 )",
      "cwe": "CWE-267",
      "title": "DS8900F and DS8A00 Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36255"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-76325",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76325"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-18231",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-200",
      "title": "WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18231"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-18778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TrueBooker",
      "cwe": "CWE-200",
      "title": "TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18778"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-16814",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16814"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-76223",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-862",
      "title": "ArcadeDB before 26.8.1 Permission Bypass via DEFINE FUNCTION",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76223"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-13169",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.15816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-639",
      "title": "Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13169"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-76388",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.15813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise Security",
      "cwe": "CWE-732",
      "title": "Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76388"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-76399",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.15816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76399"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-19417",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.15814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "KiviCare",
      "cwe": "CWE-639",
      "title": "KiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19417"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-76257",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.15814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Missing Authorization through REST API Endpoints in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76257"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-76258",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.15818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-321",
      "title": "Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76258"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-76354",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.15689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-158",
      "title": "Path Traversal through Search Head Clustering in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76354"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-76919",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.15735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-457",
      "title": "Use of Uninitialized Variable in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76919"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-76330",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.15658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "SPL Injection through Monitoring Console Forwarder Filters in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76330"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-76332",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.15658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "SPL Injection through Splunk Web in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76332"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-11751",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.15418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LY Corporation",
      "product": "Armeria",
      "cwe": null,
      "title": "A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11751"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-76351",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76351"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-73384",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.1547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsMinds",
      "product": "Pay with Contact Form 7",
      "cwe": "CWE-201",
      "title": "WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73384"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-73386",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZealousWeb",
      "product": "Track Geolocation Of Users Using Contact Form 7",
      "cwe": "CWE-201",
      "title": "WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73386"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-75981",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "TranslatePress – Translate Multilingual sites with AI Translation",
      "cwe": "CWE-79",
      "title": "TranslatePress – Translate Multilingual sites with AI Translation <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75981"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-76215",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-862",
      "title": "phpMyFAQ before 4.1.7 Missing Authorization via child resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76215"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-62670",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-flex-objects",
      "cwe": "CWE-862",
      "title": "Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62670"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-76326",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76326"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-40507",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-79",
      "title": "OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40507"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-51367",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00243,
      "epss_percentile": 0.15266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51367"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-73391",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KlbTheme",
      "product": "Total Donations",
      "cwe": "CWE-89",
      "title": "WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73391"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-54491",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.14947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koel",
      "product": "koel",
      "cwe": "CWE-918",
      "title": "Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54491"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-15446",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.14989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nosilver4u",
      "product": "EWWW Image Optimizer",
      "cwe": "CWE-79",
      "title": "EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15446"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-76336",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.1484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Improper Access Control through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76336"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-18849",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.14903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "OPENBMC",
      "cwe": "CWE-22",
      "title": "IBM OpenBMC Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18849"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-73829",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.14891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-367",
      "title": "Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73829"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-19198",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.14576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akaunting",
      "product": "Akaunting",
      "cwe": "CWE-863",
      "title": "Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19198"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-55694",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.14576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-639",
      "title": "Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55694"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-73183",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Get Maps Marker Pro",
      "product": "Maps Marker Pro",
      "cwe": "CWE-89",
      "title": "WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73183"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-73185",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpo-HR",
      "product": "NGG Smart Image Search",
      "cwe": "CWE-89",
      "title": "WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73185"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-73388",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeconceTheme",
      "product": "Nikstore Core",
      "cwe": "CWE-89",
      "title": "WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73388"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-11565",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Advanced File Manager",
      "cwe": null,
      "title": "Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11565"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-76396",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-269",
      "title": "Improper Access Control through Scheduled Searches in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76396"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-16440",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse OpenJ9",
      "cwe": "CWE-674",
      "title": "In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16440"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-16058",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YayCurrency",
      "cwe": "CWE-639",
      "title": "YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16058"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-15078",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-295",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15078"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-76323",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.13713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76323"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-76348",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00231,
      "epss_percentile": 0.1378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76348"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-76205",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.13581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-89",
      "title": "phpMyFAQ before 4.1.7 SQL Injection via Glossary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76205"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-76331",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.13579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-943",
      "title": "SPL Injection through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76331"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-19406",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.13568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-200",
      "title": "Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19406"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-76256",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-200",
      "title": "Information Exposure through REST API Endpoints in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76256"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-16835",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00228,
      "epss_percentile": 0.13327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-295",
      "title": "Power System Improper Certificate Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16835"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-76827",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-693",
      "title": "Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76827"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-76341",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.1319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-863",
      "title": "Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76341"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-76234",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.12775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "celabshq",
      "product": "libcrux-ecdh",
      "cwe": "CWE-347",
      "title": "libcrux before 0.0.6 Cryptographic Implementation Bug Fixes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76234"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-18102",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00224,
      "epss_percentile": 0.12868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-122",
      "title": "IBM i Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18102"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-19507",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00223,
      "epss_percentile": 0.12646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RDK",
      "product": "RDK-B WebUI",
      "cwe": null,
      "title": "RDK WebUI uncontrolled resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19507"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-76255",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.12607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76255"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-18777",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TrueBooker",
      "cwe": "CWE-862",
      "title": "TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18777"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-18779",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TrueBooker",
      "cwe": "CWE-862",
      "title": "TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18779"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-19506",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00221,
      "epss_percentile": 0.12437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RDK",
      "product": "RDK-B WebUI",
      "cwe": null,
      "title": "RDK-B WebUI race condition vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19506"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-49415",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.1231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-367",
      "title": "Local privilege escalation via execve(2) TOCTOU race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49415"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-12522",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12522"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-76263",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-639",
      "title": "Improper Access Control through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76263"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-14826",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quiz and Survey Master (QSM)",
      "cwe": "CWE-639",
      "title": "Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14826"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-76361",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76361"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-76368",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-862",
      "title": "Missing Authorization through Playbooks in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76368"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-75619",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.1196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C100 v5",
      "cwe": "CWE-122",
      "title": "RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75619"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-76244",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.11868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem",
      "cwe": "CWE-319",
      "title": "stigmem-node Insecure Federation Transport Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76244"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-76324",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.11845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76324"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-76309",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.11816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-89",
      "title": "Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76309"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-76209",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.1171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-862",
      "title": "phpMyFAQ before v4.1.6 Registration Bypass via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76209"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-76375",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.11648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "AD LDAP app for Splunk SOAR",
      "cwe": "CWE-532",
      "title": "Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76375"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-76374",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.11649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "AD LDAP app for Splunk SOAR",
      "cwe": "CWE-532",
      "title": "Information Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76374"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-12633",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router Advertisement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12633"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-76226",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.11635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-78",
      "title": "Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76226"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-76342",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.11505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-863",
      "title": "Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76342"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-58081",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00214,
      "epss_percentile": 0.11521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-122",
      "title": "Heap based buffer overflow in iconv(3)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58081"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-58082",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00214,
      "epss_percentile": 0.11639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-121",
      "title": "Stack based buffer overflow in iconv(3)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58082"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-76261",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-732",
      "title": "Insecure Default Access Control List through the REST API in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76261"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-55519",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-285",
      "title": "Snipe-IT: Improper Authorization in File Deletion (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55519"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-76251",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-862",
      "title": "Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76251"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-16846",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-476",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16846"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-76349",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-943",
      "title": "SPL Injection through Splunk Web Form Tokens in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76349"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-18466",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.10944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Maps",
      "cwe": "CWE-284",
      "title": "WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18466"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-76347",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.10943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76347"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-76328",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.10854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-77",
      "title": "SPL Injection through Splunk Web in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76328"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-61607",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.10794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-api",
      "cwe": "CWE-79",
      "title": "Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61607"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-16687",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00207,
      "epss_percentile": 0.10692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-121",
      "title": "Power System Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16687"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-76327",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.10672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-943",
      "title": "SPL Injection through Splunk Web in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76327"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-76320",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-943",
      "title": "SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76320"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-76360",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.1047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-862",
      "title": "Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76360"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-76370",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.1047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-863",
      "title": "Information Disclosure through the REST API in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76370"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-20327",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Unified Intelligence Center",
      "cwe": "CWE-89",
      "title": "Cisco Unified Intelligence Center SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20327"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-20232",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Industrial Ethernet Switches",
      "cwe": "CWE-80",
      "title": "Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20232"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-13173",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.10361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-862",
      "title": "Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13173"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-14825",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.10362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quiz and Survey Master (QSM)",
      "cwe": "CWE-639",
      "title": "Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14825"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-76371",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.10361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "FireAMP",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76371"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-76211",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-862",
      "title": "phpMyFAQ before 4.1.7 Information Disclosure via Admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76211"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-75583",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ridafkih",
      "product": "keeper.sh",
      "cwe": "CWE-918",
      "title": "keeper.sh Calendar version prior to 2.18.14 SSRF Guard Bypass via DNS Rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75583"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-73385",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.09989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Outanking Team",
      "product": "Outranking Plugin Options",
      "cwe": "CWE-862",
      "title": "WordPress Outranking plugin Options plugin <= 1.1.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73385"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-73394",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.09988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stitchexpress",
      "product": "Stitch Express",
      "cwe": "CWE-862",
      "title": "WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73394"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-16851",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.1003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-416",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16851"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-49430",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00202,
      "epss_percentile": 0.10024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-122",
      "title": "Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49430"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-18681",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.09843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Server Firmware",
      "cwe": "CWE-121",
      "title": "This Power System Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18681"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-19842",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.09743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SAML Single Sign On",
      "cwe": "CWE-287",
      "title": "SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19842"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-17565",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.09811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Animation Addons for Elementor",
      "cwe": "CWE-918",
      "title": "Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17565"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-54794",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.09811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-918",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54794"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-19505",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.09777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RDK",
      "product": "RDK-B WebUI",
      "cwe": null,
      "title": "RDK-B WebUI improper cryptographic signature verification vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19505"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-16822",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00199,
      "epss_percentile": 0.09686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-295",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16822"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-48711",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.09676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libfuse",
      "product": "sshfs",
      "cwe": "CWE-88",
      "title": "SSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48711"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-16849",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-129",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16849"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-16886",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16886"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-14514",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Reliable Scalable Cluster Technology (RSCT)",
      "cwe": "CWE-770",
      "title": "Reliable Scalable Cluster Technology Denial-of-Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14514"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-16979",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SmartCrawl SEO checker, analyzer & optimizer",
      "cwe": "CWE-639",
      "title": "SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16979"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-76329",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-943",
      "title": "SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76329"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-76403",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.08934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Connect for Kafka",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76403"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-75618",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.08913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C100 v5",
      "cwe": "CWE-476",
      "title": "RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75618"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-17028",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-125",
      "title": "Power System Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17028"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-63123",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinacms",
      "product": "tinacms",
      "cwe": "CWE-352",
      "title": "Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63123"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-76318",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76318"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-55703",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-862",
      "title": "Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55703"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-18821",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.08711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-787",
      "title": "Power System Out-of-bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18821"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-55482",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.08801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-639",
      "title": "Snipe-IT: Multi-Tenancy Bypass via Bulk Asset Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55482"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-49392",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.08725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-20",
      "title": "Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49392"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-16832",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-121",
      "title": "Power System Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16832"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-19416",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "KiviCare",
      "cwe": "CWE-639",
      "title": "KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19416"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-76346",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.0837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76346"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-11617",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Findings",
      "cwe": "CWE-409",
      "title": "Tanium addressed a compression bomb vulnerability in Findings.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11617"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-75476",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Threat Response",
      "cwe": "CWE-409",
      "title": "Tanium addressed a compression bomb vulnerability in Threat Response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75476"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-62727",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62727"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-17414",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-20",
      "title": "Power System Improper Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17414"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-14196",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WCFM Marketplace",
      "cwe": "CWE-639",
      "title": "WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14196"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-76398",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-862",
      "title": "Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76398"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-20302",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.07992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-120",
      "title": "Cisco RoomOS Stack Overflow Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20302"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-76252",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.07934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76252"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-75589",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07995,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-OAuth",
      "cwe": "CWE-208",
      "title": "Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75589"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-76245",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem",
      "cwe": "CWE-345",
      "title": "stigmem Federation Peer Token Timestamp Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76245"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2025-36398",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DS8A00 (R10.0 - R10.1)",
      "cwe": "CWE-73",
      "title": "DS8900F and DS8A00 Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36398"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-19782",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPS Bidouille",
      "cwe": "CWE-200",
      "title": "WPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19782"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-76373",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "AD LDAP app for Splunk SOAR",
      "cwe": "CWE-90",
      "title": "Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76373"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-16829",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-476",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16829"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-16570",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "NextScripts: Social Networks Auto-Poster",
      "cwe": "CWE-79",
      "title": "NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16570"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-19055",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProSolution WP Client",
      "cwe": "CWE-79",
      "title": "ProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19055"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-19056",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProSolution WP Client",
      "cwe": "CWE-79",
      "title": "ProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19056"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-76339",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-77",
      "title": "SPL Injection through the geostats Command in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76339"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-76362",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76362"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-76926",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.0736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-617",
      "title": "Reachable Assertion in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76926"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-49431",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.07295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-863",
      "title": "Incorrect user validation in ZFS_IOC_SET_PROP ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49431"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-50550",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: 2FA reset privilege bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50550"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-76884",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.06937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76884"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-76885",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.06936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76885"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-76887",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.06936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76887"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-76888",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.06936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76888"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-76890",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.06937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-825",
      "title": "Expired Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76890"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-76891",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.06937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-825",
      "title": "Expired Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76891"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-16828",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.0686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-125",
      "title": "Power System Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16828"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-73363",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.06923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Taxi Booking Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73363"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-40508",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-79",
      "title": "OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40508"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-16724",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Virtualization Management Interface",
      "cwe": "CWE-190",
      "title": "Power System Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16724"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-76392",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76392"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-66358",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extra Innovation Inc.",
      "product": "acmailer CGI",
      "cwe": "CWE-79",
      "title": "A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66358"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-14287",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "10Web Booster",
      "cwe": "CWE-79",
      "title": "TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14287"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-49429",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.05884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-122",
      "title": "Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49429"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-54793",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.05933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Enterprise",
      "cwe": "CWE-79",
      "title": "Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54793"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-76647",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00165,
      "epss_percentile": 0.05857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "JSON-RPC API",
      "cwe": null,
      "title": "Leantime JSON-RPC API contains a missing authorization vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76647"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-16875",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.05742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16875"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2024-13942",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockchip",
      "product": "RK3588s",
      "cwe": "CWE-367",
      "title": "Rockchip RK3588s Secure BootROM TOCTOU (time-of-check to time-of-use) vulnerability leading to arbitrary code execution with highest privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-13942"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-75917",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00162,
      "epss_percentile": 0.0564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.7.4 XSS-to-RCE via pathName.ts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75917"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-19509",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RDK",
      "product": "RDK-B WebUI",
      "cwe": null,
      "title": "RDK WebUI DOS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19509"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-75916",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00159,
      "epss_percentile": 0.05242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan XSS-to-RCE via unescaped block metadata in hint popup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75916"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-43961",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43961"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-75952",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75952"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-22306",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00154,
      "epss_percentile": 0.04756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ozols Grupa",
      "product": "OZOLS",
      "cwe": "CWE-319",
      "title": "Critical flaw impacting OZOLS ERP's automatic update channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22306"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-76383",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "RSA SecurID Authentication Manager app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76383"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-75148",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jkuhlmann",
      "product": "cgltf",
      "cwe": "CWE-190",
      "title": "cgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75148"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-76367",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76367"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-49423",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-908",
      "title": "Remote DOS via uninitialized memory access in KTLS receive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49423"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-49424",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-908",
      "title": "Kernel stack disclosure in Linux compatibility layer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49424"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-49425",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-908",
      "title": "Kernel stack disclosure in 32-bit compatibility support",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49425"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-49426",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-223",
      "title": "Incorrect audit records for ptrace(2) syscall requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49426"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-50719",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50719"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-50720",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data. This allows an attacker with physical write access to boot media to forge modified SPL (Secondary Program Loader) images that pass secure boot verification without possession of the OEM signing key. Each forgery attempt succeeds with approximately 2/3 probability. This has been validated via reverse engineering, software emulation against vendor-signed images, and end-to-end hardware acceptance of a forged firmware image on a Wyze Video Doorbell v2 (T31X).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50720"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-75953",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie.com",
      "product": "J-BusinessDirectory extension for Joomla",
      "cwe": "CWE-201",
      "title": "Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75953"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-50149",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcontour",
      "product": "contour",
      "cwe": "CWE-295",
      "title": "Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50149"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-61986",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker",
      "product": "Contest Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61986"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-66596",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stefano Lissa",
      "product": "Newsletter",
      "cwe": "CWE-79",
      "title": "WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66596"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-73182",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jeff Starr",
      "product": "BBQ Pro",
      "cwe": "CWE-79",
      "title": "WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73182"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-73184",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LCweb",
      "product": "Global Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Global Gallery plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73184"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-73354",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ReichertBrothers",
      "product": "SimplyRETS Real Estate IDX",
      "cwe": "CWE-79",
      "title": "WordPress SimplyRETS Real Estate IDX plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73354"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-76378",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Cisco Secure Malware Analytics app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76378"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-76379",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Cisco Webex app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in Cisco Webex app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76379"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-58084",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00143,
      "epss_percentile": 0.0385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-908",
      "title": "Kernel stack disclosure via timer_settime(2)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58084"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-58085",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00142,
      "epss_percentile": 0.03695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-347",
      "title": "Missing MAC validation in wg(4) packet decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58085"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-58086",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00142,
      "epss_percentile": 0.03743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-273",
      "title": "ktrace(2) privilege incorrectly validated in jails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58086"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-76376",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "AWS IAM app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76376"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-76377",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Azure AD Graph app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76377"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-76380",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "CrowdStrike OAuth API app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in CrowdStrike OAuth API app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76380"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-76381",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "MS Graph for Active Directory app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in MS Graph for Active Directory app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76381"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-76382",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Phantom app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in Phantom app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76382"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-76384",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Attack Analyzer Connector for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76384"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-76386",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Zoom app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in Zoom app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76386"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-76405",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk On-Call (VictorOps)",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76405"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-16938",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-862",
      "title": "Power System Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16938"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-75141",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-122",
      "title": "FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75141"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-75142",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-121",
      "title": "FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75142"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-75144",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-122",
      "title": "FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75144"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-16914",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16914"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-72889",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00137,
      "epss_percentile": 0.03308,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-OAuth",
      "cwe": "CWE-347",
      "title": "Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72889"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-76393",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-362",
      "title": "Race Condition during Model Upload through the REST API in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76393"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-62671",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-login",
      "cwe": "CWE-352",
      "title": "CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on task=login.regenerate2FASecret)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62671"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-16661",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.02978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-190",
      "title": "Power System Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16661"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-16707",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.02979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-125",
      "title": "Power System Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16707"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-49421",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00132,
      "epss_percentile": 0.0298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-273",
      "title": "unlinkat(2) ignores AT_RESOLVE_BENEATH flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49421"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-68554",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00131,
      "epss_percentile": 0.02898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-345",
      "title": "Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68554"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-52834",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.02876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tirr-c",
      "product": "jxl-oxide",
      "cwe": "CWE-122",
      "title": "jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platforms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52834"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-76259",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-269",
      "title": "Improper Privilege Management on the Management Port in Splunk Enterprise for Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76259"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-40509",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-352",
      "title": "OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40509"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-16874",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16874"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-49422",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Use-after-free in TCP RACK stack option handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49422"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-76334",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-352",
      "title": "SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76334"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-16869",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-426",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16869"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-58083",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Use-after-free in kqueue copy-on-fork",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58083"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-16933",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-190",
      "title": "Power System Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16933"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-19234",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-121",
      "title": "Power System Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19234"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-56796",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-59",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56796"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-65610",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00123,
      "epss_percentile": 0.02325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nnn",
      "product": "nnn",
      "cwe": "CWE-197",
      "title": "Numeric Truncation Error in nnn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65610"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-55086",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ether",
      "product": "etherpad",
      "cwe": "CWE-59",
      "title": "Etherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55086"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-58087",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.0211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-125",
      "title": "Heap out-of-bounds access in semctl(2)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58087"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-75147",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-125",
      "title": "FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75147"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-14978",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "go-slug",
      "cwe": "CWE-176",
      "title": "Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14978"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-76014",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "BusyBox",
      "cwe": "CWE-404",
      "title": "BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76014"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-16873",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.0203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16873"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-49817",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-502",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49817"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-16930",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-862",
      "title": "Power System Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16930"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-76921",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-416",
      "title": "Use After Free in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76921"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-17063",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-863",
      "title": "Power System Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17063"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-75145",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-681",
      "title": "FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75145"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-17091",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-190",
      "title": "Power System Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17091"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-76227",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-526",
      "title": "Renovate 42.68.1 before 42.96.3 Environment Variable Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76227"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-17093",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-121",
      "title": "Power System Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17093"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-17100",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-787",
      "title": "Power System Out-of-bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17100"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-17494",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-121",
      "title": "Power System Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17494"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-65609",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00115,
      "epss_percentile": 0.01704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nnn",
      "product": "nnn",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in nnn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65609"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-16883",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16883"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-75112",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "OTTO® Fleet Manager",
      "cwe": "CWE-916",
      "title": "OTTO® Fleet Manager – Weak Password Hashing Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75112"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-49816",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-502",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49816"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-16897",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-369",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16897"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-75900",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75900"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-17097",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-129",
      "title": "Power System Improper Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17097"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-18871",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.0139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-121",
      "title": "Power System Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18871"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-19321",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-190",
      "title": "Power System Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19321"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-76924",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76924"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-58088",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-362",
      "title": "Race condition in ELF core dump segment counting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58088"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-16891",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00106,
      "epss_percentile": 0.01224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16891"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-17042",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00105,
      "epss_percentile": 0.01176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-125",
      "title": "Power System Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17042"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-76917",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76917"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-76918",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76918"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-76922",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76922"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-76923",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76923"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-12634",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.0116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12634"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-76881",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76881"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-76882",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76882"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-17429",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-863",
      "title": "Power System Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17429"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-8810",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Insyde Software",
      "product": "InsydeH2O, InsydeH2O ARM",
      "cwe": "CWE-522",
      "title": "HDD Password leakage vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8810"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-67268",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-611",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67268"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-16855",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.0101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16855"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-67267",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-497",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67267"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-18848",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Power Systems Firmware",
      "cwe": "CWE-352",
      "title": "Power System Cross-Site Request Forgery (CSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18848"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-19653",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19653"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-76927",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76927"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-76929",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76929"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-4937",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.0086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-331",
      "title": "Power System Insufficient Entropy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4937"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-76883",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76883"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-76889",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76889"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-76920",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.0083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76920"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-15961",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-134",
      "title": "Power System Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15961"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-16703",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16703"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-58565",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-862",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58565"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-58564",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-276",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58564"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-58562",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00092,
      "epss_percentile": 0.00569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-862",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58562"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-76385",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.0059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Venafi app for Splunk SOAR",
      "cwe": "CWE-312",
      "title": "Information Disclosure through Action Parameters in Venafi app for Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76385"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-16890",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00092,
      "epss_percentile": 0.00579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-190",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16890"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-32802",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerPath",
      "cwe": "CWE-269",
      "title": "Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32802"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-76241",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00088,
      "epss_percentile": 0.00443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eidetic-labs",
      "product": "stigmem",
      "cwe": "CWE-494",
      "title": "stigmem Plugin Signature Enforcement Bypass via Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76241"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-16819",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00087,
      "epss_percentile": 0.00403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-367",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16819"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-53477",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00084,
      "epss_percentile": 0.00293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-367",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53477"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-67266",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00084,
      "epss_percentile": 0.00322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-863",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67266"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-56797",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00082,
      "epss_percentile": 0.00254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Command Update (DCU)",
      "cwe": "CWE-367",
      "title": "Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56797"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-16838",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00081,
      "epss_percentile": 0.00227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-367",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16838"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-4936",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00074,
      "epss_percentile": 0.00076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-331",
      "title": "Power System Insufficient Entropy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4936"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-64849",
      "detail": "ADDED TO KEV — CVE-2026-64849 (mlflow). Remediation due September 2, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20252",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20252 (nextgeneditor NextGen Editor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20253",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20253 (Gegabyte My Projects). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20254",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20254 (Gegabyte User Bench). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20255",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20255 (Joombooking JB Visa). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20256",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20256 (Joomplace Survey Force Deluxe). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20257",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20257 (Joomplace Quiz Deluxe). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20258",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20258 (Extro RPC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20259",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20259 (Joomlashack OSDownloads). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20260",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20260 (Weborange Price Alert). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20261",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20261 (Weborange Bargain Product VM3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20262",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20262 (Webkul Ajax Quiz). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20263",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20263 (Focalpointx FocalPoint Pro / Free). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20264",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20264 (Pulseextensions Sponsor Wall). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20265",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20265 (Pulseextensions Flip Wall). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20266",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20266 (Joomshaper SP Movie Database). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20267",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20267 (Joomlathat Calendar Planner). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20272",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20272 (Faboba Ultimate Property Listing). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20274",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20274 (King-products LMS King Professional). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20276",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20276 (Simbunch SIMGenealogy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20277",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20277 (Joomboost Joomla JoomRecipe). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20278",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20278 (Joomboost JoomRecipe). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20279",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20279 (Extensions Joomla Payage). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20280",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20280 (Myportfolio). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20281",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20281 (Joomlaboat Extra Search). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20282",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20282 (Soft-Php jCart for OpenCart). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25748",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25748 (Cmsjunkie JHotelReservation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25749",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25749 (Cmsjunkie J-CruisePortal). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25750",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25750 (Cmsjunkie MultipleHotelReservation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25751",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25751 (Cmsjunkie ClassifiedsManager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25752",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25752 (Cmsjunkie J-BusinessDirectory). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25753",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25753 (Wdmtech VMap). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-1048",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-1048 (Microsoft Windows 10 Version 1507). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-1054",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-1054 (Microsoft Windows 10 Version 1507). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-1106",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-1106 (Microsoft SharePoint Enterprise Server 2016). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-26855",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-26855 (Microsoft Exchange Server 2013 Cumulative Update 21). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-26863",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-26863 (Microsoft Windows 10 Version 1803). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-27065",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-27065 (Microsoft Exchange Server 2013 Cumulative Update 21). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-27074",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-27074 (Microsoft Azure Sphere). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-27080",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-27080 (Microsoft Azure Sphere). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-42297",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-42297 (Microsoft Windows Update Assistant). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-42321",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-42321 (Microsoft Exchange Server 2016 Cumulative Update 21). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-26485",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-26485 (Mozilla Firefox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-26486",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-26486 (Mozilla Firefox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12228",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12228 (parisneo/lollms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17106",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17106 (moby go-archive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5241 (huggingface/transformers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70667",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70667 (Netflix lemur). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72529",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72529 (TrueConf Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72530",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75086",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75086 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75093",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75093 (sonos tract). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75130",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75130 (Uptash Context7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75773",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75773 (karakeep-app karakeep). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75778",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75778 (code-projects Task Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75784",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75784 (TRENDnet TEW-WLC100). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75876",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75876 (xianrendzw EasyReport). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75877",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75877 (TRENDnet TV-IP751WIC). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2020-1106",
      "detail": "RESCORED — CVE-2020-1106 (Microsoft SharePoint Enterprise Server 2016). CVSS 5.4 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-21695",
      "detail": "RESCORED — CVE-2023-21695 (Microsoft Windows 10 Version 1507). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-21697",
      "detail": "RESCORED — CVE-2023-21697 (Microsoft Windows 10 Version 1507). CVSS 6.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-21703",
      "detail": "RESCORED — CVE-2023-21703 (Microsoft Azure Data Box Gateway). CVSS 6.5 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43481",
      "detail": "RESCORED — CVE-2024-43481 (Microsoft Power BI Report Server - May 2024). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-43612",
      "detail": "RESCORED — CVE-2024-43612 (Microsoft Power BI Report Server - May 2024). CVSS 6.9 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12228",
      "detail": "RESCORED — CVE-2026-12228 (parisneo/lollms). CVSS 8.7 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16627",
      "detail": "RESCORED — CVE-2026-16627 (GitLab). CVSS 7.7 → 9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17074",
      "detail": "RESCORED — CVE-2026-17074 (IBM i). CVSS 3.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17075",
      "detail": "RESCORED — CVE-2026-17075 (IBM i). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17101",
      "detail": "RESCORED — CVE-2026-17101 (IBM i). CVSS 8.3 → 9.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17272",
      "detail": "RESCORED — CVE-2026-17272 (IBM i). CVSS 8.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17476",
      "detail": "RESCORED — CVE-2026-17476 (IBM i). CVSS 4.8 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17502",
      "detail": "RESCORED — CVE-2026-17502 (IBM i). CVSS 8.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18086",
      "detail": "RESCORED — CVE-2026-18086 (IBM i). CVSS 4.5 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18193",
      "detail": "RESCORED — CVE-2026-18193 (IBM i). CVSS 8.9 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18249",
      "detail": "RESCORED — CVE-2026-18249 (IBM i). CVSS 8.4 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-21229",
      "detail": "RESCORED — CVE-2026-21229 (Microsoft Power BI Report Server). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48617",
      "detail": "RESCORED — CVE-2026-48617 (nodejs node). CVSS 1.8 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7427",
      "detail": "RESCORED — CVE-2026-7427 (GitLab). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75587",
      "detail": "RESCORED — CVE-2026-75587 (Mattermost). CVSS 3.6 → 3.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75976",
      "detail": "RESCORED — CVE-2026-75976 (TRENDnet TEW-823DRU). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71225",
      "detail": "PATCH SHIPPED — CVE-2026-71225 (Stephan Muelle libkcapi). Fixed in Red Hat Hardened Images 1.5.1-0.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71226",
      "detail": "PATCH SHIPPED — CVE-2026-71226 (Stephan Muelle libkcapi). Fixed in Red Hat Hardened Images 1.5.1-0.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71227",
      "detail": "PATCH SHIPPED — CVE-2026-71227 (Stephan Muelle libkcapi). Fixed in Red Hat Hardened Images 1.5.1-0.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-72694",
      "detail": "PATCH SHIPPED — CVE-2026-72694 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:2.17.10-12.el10_2.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-74012",
      "detail": "PATCH SHIPPED — CVE-2026-74012 (TaxoPress). Fixed in TaxoPress 3.52.0."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-0901",
      "detail": "ENRICHED — CVE-2020-0901 (Microsoft 365 Apps for Enterprise). Received CVSS 9.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1023",
      "detail": "ENRICHED — CVE-2020-1023 (Microsoft SharePoint Enterprise Server 2016). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1024",
      "detail": "ENRICHED — CVE-2020-1024 (Microsoft SharePoint Enterprise Server 2016). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1063",
      "detail": "ENRICHED — CVE-2020-1063 (Microsoft Dynamics 365 (on-premises) version 8.2). Received CVSS 5.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1066",
      "detail": "ENRICHED — CVE-2020-1066 (Microsoft .NET Framework 3.0 Service Pack 2). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1069",
      "detail": "ENRICHED — CVE-2020-1069 (Microsoft SharePoint Enterprise Server 2016). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1102",
      "detail": "ENRICHED — CVE-2020-1102 (Microsoft SharePoint Enterprise Server 2016). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1103",
      "detail": "ENRICHED — CVE-2020-1103 (Microsoft SharePoint Enterprise Server 2016). Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1104",
      "detail": "ENRICHED — CVE-2020-1104 (Microsoft SharePoint Enterprise Server 2016). Received CVSS 5.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1105",
      "detail": "ENRICHED — CVE-2020-1105 (Microsoft SharePoint Enterprise Server 2016). Received CVSS 5.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1107",
      "detail": "ENRICHED — CVE-2020-1107 (Microsoft SharePoint Enterprise Server 2013 Service Pack 1). Received CVSS 5.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1108",
      "detail": "ENRICHED — CVE-2020-1108 (Microsoft .NET 5.0). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1161",
      "detail": "ENRICHED — CVE-2020-1161 (Microsoft ASP.NET Core 3.1). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1171",
      "detail": "ENRICHED — CVE-2020-1171 (Microsoft Python extension for Visual Studio Code). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1173",
      "detail": "ENRICHED — CVE-2020-1173 (Microsoft Power BI Report Server). Received CVSS 6.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1179",
      "detail": "ENRICHED — CVE-2020-1179 (Microsoft Windows 10 Version 1507). Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-1192",
      "detail": "ENRICHED — CVE-2020-1192 (Microsoft Visual Studio Code). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23394",
      "detail": "ENRICHED — CVE-2026-23394 (Linux). Received CVSS 4.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43491",
      "detail": "ENRICHED — CVE-2026-43491 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
