{
  "day": "2026-08-20",
  "boundary": "UTC calendar day",
  "published_count": 468,
  "by_severity": {
    "CRITICAL": 72,
    "HIGH": 214,
    "MEDIUM": 150,
    "LOW": 25
  },
  "kev_count": 0,
  "exploit_reference_count": 5,
  "awaiting_enrichment_count": 7,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-19586",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.05035,
      "epss_percentile": 0.91611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "ER7212PC v2",
      "cwe": "CWE-78",
      "title": "Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19586"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-69836",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01589,
      "epss_percentile": 0.73743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-502",
      "title": "Microsoft Entra ID Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69836"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-77031",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01318,
      "epss_percentile": 0.68617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH22",
      "cwe": "CWE-74",
      "title": "Tenda CH22 formcreateFileName command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77031"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-18274",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01295,
      "epss_percentile": 0.6813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Heimdall Data",
      "product": "Database Proxy",
      "cwe": "CWE-22",
      "title": "Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18274"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-77004",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01282,
      "epss_percentile": 0.6786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfast",
      "product": "CF-N1-S",
      "cwe": "CWE-74",
      "title": "Comfast CF-N1-S mbox-config sprintf command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77004"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-53804",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01248,
      "epss_percentile": 0.67045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Centuran Consulting",
      "product": "OTRS Community Edition",
      "cwe": "CWE-78",
      "title": "OTRS Community Edition OS Command Injection via PGP Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53804"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-18264",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01242,
      "epss_percentile": 0.66896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NoMachine",
      "product": "NoMachine",
      "cwe": "CWE-78",
      "title": "NoMachine getstat Command Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18264"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-19446",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01033,
      "epss_percentile": 0.61203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19446"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-14947",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0094,
      "epss_percentile": 0.58274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-24",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14947"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-18272",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00881,
      "epss_percentile": 0.5641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenwood",
      "product": "DNR1007XR",
      "cwe": "CWE-78",
      "title": "Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18272"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-77647",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00816,
      "epss_percentile": 0.54334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPIP",
      "product": "SPIP",
      "cwe": "CWE-94",
      "title": "SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77647"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2025-14601",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00803,
      "epss_percentile": 0.53929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vsDesk",
      "product": "vsDesk",
      "cwe": "CWE-676",
      "title": "vsDesk Task Scheduler OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14601"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-18482",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00753,
      "epss_percentile": 0.52271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Klarso GmbH",
      "product": "neo-mjs",
      "cwe": null,
      "title": "CVE-2026-18482",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18482"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-73992",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00736,
      "epss_percentile": 0.51684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jonathan Daggerhart",
      "product": "Query Wrangler",
      "cwe": "CWE-94",
      "title": "WordPress Query Wrangler plugin <= 1.5.57 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73992"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-15686",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00724,
      "epss_percentile": 0.51288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adminer",
      "product": "Adminer",
      "cwe": "CWE-253",
      "title": "Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15686"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-18265",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00692,
      "epss_percentile": 0.50087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OSNEXUS",
      "product": "QuantaStor",
      "cwe": "CWE-306",
      "title": "OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18265"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-73040",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0067,
      "epss_percentile": 0.49203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "louislam",
      "product": "dockge",
      "cwe": "CWE-22",
      "title": "Dockge Path Traversal via Unvalidated Stack Name Allows Arbitrary Compose and .env Disclosure and Arbitrary Directory Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73040"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-18420",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00664,
      "epss_percentile": 0.48958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amazon OpenSearch Service",
      "cwe": "CWE-1321",
      "title": "RCE via Prototype Pollution in OpenSearch Dashboards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18420"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-63509",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00621,
      "epss_percentile": 0.47082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Fabric",
      "cwe": "CWE-23",
      "title": "Microsoft Fabric Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63509"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-17136",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00599,
      "epss_percentile": 0.46014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-134",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17136"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-14950",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00598,
      "epss_percentile": 0.45951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-613",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14950"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-73255",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00594,
      "epss_percentile": 0.45742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-22",
      "title": "Mongoose: Path traversal in SSI #include directives enables arbitrary file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73255"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-17142",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00593,
      "epss_percentile": 0.45721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-287",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17142"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-72843",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0059,
      "epss_percentile": 0.4558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "evershopcommerce",
      "product": "evershop",
      "cwe": "CWE-862",
      "title": "EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72843"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-63382",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00587,
      "epss_percentile": 0.45431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-444",
      "title": "libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63382"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-69519",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.45188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Stack HCI",
      "cwe": "CWE-204",
      "title": "Azure Stack HCI Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69519"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-65770",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00578,
      "epss_percentile": 0.44949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Managed Instance for Apache Cassandra",
      "cwe": "CWE-88",
      "title": "Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65770"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-69400",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00573,
      "epss_percentile": 0.44722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Logic Apps",
      "cwe": "CWE-22",
      "title": "Azure Logic Apps Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69400"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-18835",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00564,
      "epss_percentile": 0.44268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18835"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-17122",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00562,
      "epss_percentile": 0.44168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17122"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-17141",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00562,
      "epss_percentile": 0.44167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17141"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-17152",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00562,
      "epss_percentile": 0.44167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17152"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-17157",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00562,
      "epss_percentile": 0.44168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17157"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-69558",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Partner Center",
      "cwe": "CWE-639",
      "title": "Microsoft Partner Center Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69558"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-66800",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Data Factory",
      "cwe": "CWE-918",
      "title": "Azure Data Factory Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66800"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-75484",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00549,
      "epss_percentile": 0.43465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mtrudel",
      "product": "bandit",
      "cwe": "CWE-93",
      "title": "HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75484"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-18284",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00548,
      "epss_percentile": 0.43402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "XAV-9500ES",
      "cwe": "CWE-78",
      "title": "Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18284"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-17160",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00546,
      "epss_percentile": 0.43309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-190",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17160"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-55769",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00544,
      "epss_percentile": 0.43225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudnative-pg",
      "product": "cloudnative-pg",
      "cwe": "CWE-426",
      "title": "CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55769"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-68782",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00541,
      "epss_percentile": 0.43027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-89",
      "title": "Azure SQL Database Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68782"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-70105",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00539,
      "epss_percentile": 0.42951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70105"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-64966",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00537,
      "epss_percentile": 0.42813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-22",
      "title": "Path Traversal leading to Remote Code Execution in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64966"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-65816",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00534,
      "epss_percentile": 0.42694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Web Apps",
      "cwe": "CWE-706",
      "title": "Azure Arc Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65816"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-68789",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0053,
      "epss_percentile": 0.42384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-89",
      "title": "Azure SQL Database Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68789"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-75140",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jhy",
      "product": "soup",
      "cwe": "CWE-770",
      "title": "jsoup Uncontrolled Resource Consumption in XmlTreeBuilder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75140"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-2334",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00524,
      "epss_percentile": 0.42066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vsDesk",
      "product": "vsDesk",
      "cwe": "CWE-434",
      "title": ") Missing Server-Side File Extension Validation in vsDesk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2334"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-65801",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.41946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Online",
      "cwe": "CWE-918",
      "title": "Microsoft Exchange Online Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65801"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-14946",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00521,
      "epss_percentile": 0.41894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-434",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious configuration file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14946"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-15049",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00521,
      "epss_percentile": 0.41894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Depicter — Popup & Slider Builder",
      "cwe": "CWE-434",
      "title": "Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15049"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-75963",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00518,
      "epss_percentile": 0.4168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liedekef",
      "product": "Events Made Easy",
      "cwe": "CWE-98",
      "title": "Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75963"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-63379",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00518,
      "epss_percentile": 0.41712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-444",
      "title": "Libevent: HTTP Header smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63379"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-76022",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00512,
      "epss_percentile": 0.41278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76022"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-17145",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00505,
      "epss_percentile": 0.40805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17145"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-72818",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.40816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-1333",
      "title": "NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72818"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-55015",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.40741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Remote Help",
      "cwe": "CWE-427",
      "title": "Microsoft Remote Help Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55015"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-76023",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00498,
      "epss_percentile": 0.4043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-913",
      "title": "Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76023"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-14952",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00496,
      "epss_percentile": 0.4028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-306",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14952"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-74836",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mtrudel",
      "product": "bandit",
      "cwe": "CWE-770",
      "title": "HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74836"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-76021",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0049,
      "epss_percentile": 0.39924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76021"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-77068",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.39458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n before 2.34.1 Remote Code Execution via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77068"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-66309",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-284",
      "title": "Azure SQL Database Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66309"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-69855",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Copilot in Azure",
      "cwe": "CWE-918",
      "title": "Microsoft Copilot in Azure Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69855"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-72848",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.38961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langchain-community",
      "cwe": "CWE-918",
      "title": "langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Sitemap Index Entries, Allowing Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72848"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-77645",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00472,
      "epss_percentile": 0.38716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PTC",
      "product": "Windchill PDMLink",
      "cwe": "CWE-20",
      "title": "Critical Remote Code Execution (RCE) vulnerability reported in Windchill",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77645"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-77148",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.3873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfast",
      "product": "CF-N1-S",
      "cwe": "CWE-119",
      "title": "Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77148"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-63490",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jknack",
      "product": "handlebars.java",
      "cwe": "CWE-22",
      "title": "Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63490"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-76017",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76017"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-18268",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenwood",
      "product": "DNR1007XR",
      "cwe": "CWE-78",
      "title": "Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18268"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-66002",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00468,
      "epss_percentile": 0.38413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-204",
      "title": "Frappe: User Enumeration via PDDR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66002"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-40345",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RebeccaStevens",
      "product": "deepmerge-ts",
      "cwe": "CWE-674",
      "title": "deepmerge-ts: Stack exhaustion when merging recursive object graphs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40345"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-63481",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00467,
      "epss_percentile": 0.38331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Orange-OpenSource",
      "product": "hurl",
      "cwe": "CWE-201",
      "title": "Hurl: Cookies in Cookies section leak when redirecting to a different host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63481"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-77022",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfast",
      "product": "CF-N1-S",
      "cwe": "CWE-121",
      "title": "Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77022"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-75514",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00462,
      "epss_percentile": 0.38013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bunkerity",
      "product": "bunkerweb",
      "cwe": "CWE-350",
      "title": "BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75514"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-17040",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.37613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-120",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17040"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-17138",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.3763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-121",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17138"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-19437",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.37595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19437"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-69555",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00452,
      "epss_percentile": 0.37316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure ARC",
      "cwe": "CWE-863",
      "title": "Azure Arc Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69555"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-74014",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.36966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "indithemes",
      "product": "IT Residence",
      "cwe": "CWE-434",
      "title": "WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74014"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-74016",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.36964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themagnifico52",
      "product": "Smart Cleaning",
      "cwe": "CWE-434",
      "title": "WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74016"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-74018",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.36966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themagnifico52",
      "product": "Warehouse Cargo",
      "cwe": "CWE-434",
      "title": "WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74018"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-17118",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.36655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-416",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17118"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-69851",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00436,
      "epss_percentile": 0.36095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-918",
      "title": "Microsoft Entra ID Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69851"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-18279",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "XAV-9500ES",
      "cwe": "CWE-120",
      "title": "Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18279"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-18824",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00427,
      "epss_percentile": 0.35348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18824"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-63495",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-400",
      "title": "Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63495"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-54505",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00426,
      "epss_percentile": 0.35256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-79",
      "title": "TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54505"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-71485",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00423,
      "epss_percentile": 0.3501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "centrifugal",
      "product": "centrifugo",
      "cwe": "CWE-290",
      "title": "Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71485"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-18307",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-122",
      "title": "GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18307"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-76018",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.34936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-250",
      "title": "Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76018"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-17168",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.34627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17168"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-76988",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.34605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liftoff-sr",
      "product": "CIPster",
      "cwe": "CWE-119",
      "title": "liftoff-sr CIPster ForwardOpen cipconnectionmanager.cc forward_open out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76988"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-76989",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.34606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liftoff-sr",
      "product": "CIPster",
      "cwe": "CWE-119",
      "title": "liftoff-sr CIPster TCP Encapsulation Receive Path encap.cc out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76989"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-76019",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.34086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76019"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-77176",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.33902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-73",
      "title": "Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77176"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-54449",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.33786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langbot-app",
      "product": "LangBot",
      "cwe": "CWE-77",
      "title": "LangBot: Authenticated RCE Via MCP Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54449"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-74001",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.33263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPEverest",
      "product": "User Registration & Membership Pro",
      "cwe": "CWE-288",
      "title": "WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74001"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-63385",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-444",
      "title": "Libevent: HTTP header handling bugs create risk of access control bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63385"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-17000",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-287",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17000"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-61704",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-Engineering",
      "product": "link-preview-js",
      "cwe": "CWE-918",
      "title": "link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61704"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-14948",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.004,
      "epss_percentile": 0.32841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-532",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14948"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-73256",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.32553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-444",
      "title": "Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73256"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-76799",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.3246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Login Registration System",
      "cwe": "CWE-425",
      "title": "code-projects Login Registration System SQL Database Backup login_registration_system.sql file access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76799"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-64960",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-434",
      "title": "Remote Code Execution via Unrestricted File Upload in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64960"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-17425",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17425"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-64963",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00393,
      "epss_percentile": 0.32104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-22",
      "title": "Path Traversal in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64963"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-53587",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.31967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libgit2",
      "product": "libgit2",
      "cwe": "CWE-20",
      "title": "libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53587"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-18302",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.3168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-122",
      "title": "GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18302"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-18303",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.3168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-121",
      "title": "GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18303"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-17121",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.31461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17121"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-17159",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.31461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-190",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17159"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-17163",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.31461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-770",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17163"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-17165",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.31462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-476",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17165"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-17170",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.31462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-770",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17170"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-66583",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Forminator",
      "cwe": "CWE-502",
      "title": "WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66583"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-66672",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monkeysan",
      "product": "Flatastic",
      "cwe": "CWE-502",
      "title": "WordPress Flatastic theme <= 2.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66672"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-73993",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roxnor",
      "product": "FundEngine",
      "cwe": "CWE-502",
      "title": "WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73993"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-16520",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genians",
      "product": "Genian NAC V4.0",
      "cwe": "CWE-20",
      "title": "Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass. This issue affects Genian NAC V4.0: from 4.0.0 before 4.0.175(Revision 150340); Genian NAC V5.0: from 5.0.0 before 5.0.65 LTS(Revision 150331), from 5.0.0 before 5.0.75 LTS(Revision 150330), from 5.0.0 before 5.0.87 Release Stable(Revision 150329), and from 5.0.0 before 5.0.88(Revision 150328); Genian ZTNA V6.0: from 6.0.0 before 6.0.26 LTS(Revision 150337), from 6.0.0 before 6.0.35 LTS(Revision 150336), from 6.0.0 before 6.0.47 Release Stable(Revision 150334), and from 6.0.0 before 6.0.48(Revision 150333).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16520"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-63383",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-125",
      "title": "Libevent: decode_tag_internal() can lead to out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63383"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-63384",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-190",
      "title": "Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63384"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-16972",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-287",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16972"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-69419",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Data Manager for Energy",
      "cwe": "CWE-190",
      "title": "Azure Data Manager for Energy Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69419"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-73257",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00376,
      "epss_percentile": 0.30302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-444",
      "title": "Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73257"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-55642",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.29907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "t8y2",
      "product": "dbx",
      "cwe": "CWE-306",
      "title": "dbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55642"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-66677",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.29957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VaultDweller",
      "product": "Leyka",
      "cwe": "CWE-288",
      "title": "WordPress Leyka plugin <= 3.32.3 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66677"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-67447",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.2988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-770",
      "title": "Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67447"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-67445",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.2983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-400",
      "title": "Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67445"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-67446",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.2983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-400",
      "title": "Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67446"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-75910",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.29725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Athena Federated Query Clickhouse Connector deployment template",
      "cwe": "CWE-266",
      "title": "Incorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75910"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-49244",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.29689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "drakkan",
      "product": "sftpgo",
      "cwe": "CWE-22",
      "title": "SFTPGo: Path confinement bypass in public browsable share partial ZIP download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49244"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-64961",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.29498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-639",
      "title": "Authentication Bypass in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64961"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-17120",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00363,
      "epss_percentile": 0.2895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17120"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-18285",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.28911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aeon",
      "product": "aeon",
      "cwe": "CWE-502",
      "title": "Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18285"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-64967",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.28725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-22",
      "title": "Path Traversal in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64967"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-64971",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.28708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-79",
      "title": "Reflected XSS in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64971"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-18304",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18304"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-18305",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18305"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-18670",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.28512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-190",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18670"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-77077",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.28494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-94",
      "title": "n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77077"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-15706",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00353,
      "epss_percentile": 0.27944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Baylan Measuring Instruments Industry and Trade Inc.",
      "product": "Baylan Smart Meter Management Application (BMS)",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15706"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-76635",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.27899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baserproject",
      "product": "basercms",
      "cwe": "CWE-89",
      "title": "baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76635"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-76795",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.27793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AeternaLabsHQ",
      "product": "PullMD",
      "cwe": "CWE-918",
      "title": "AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76795"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2025-15637",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge Themes",
      "product": "Shuffle",
      "cwe": "CWE-98",
      "title": "WordPress Shuffle theme <= 1.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15637"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-28150",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uxper",
      "product": "Golo Framework",
      "cwe": "CWE-98",
      "title": "WordPress Golo Framework plugin < 1.7.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28150"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-77646",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PTC",
      "product": "Windchill PDMLink",
      "cwe": "CWE-502",
      "title": "Server Side Request Forgery (SSRF) vulnerability reported in Windchill",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77646"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-73197",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73197"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-73198",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73198"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-76020",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76020"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-54136",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "windmill-labs",
      "product": "windmill",
      "cwe": "CWE-863",
      "title": "Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54136"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-19611",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.26973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel 4 for Quarkus 3",
      "cwe": "CWE-173",
      "title": "Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19611"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-54623",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-cms",
      "product": "django-cms",
      "cwe": "CWE-674",
      "title": "django CMS: Plugin move endpoint allows cyclic reparenting (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54623"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-63387",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-121",
      "title": "Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63387"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-13097",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.26925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-706",
      "title": "Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13097"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-53424",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.26943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dropbox",
      "product": "samly",
      "cwe": "CWE-294",
      "title": "Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53424"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-66600",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.26751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-434",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.39 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66600"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-66594",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lukeseager",
      "product": "WordPress Persistent Login",
      "cwe": "CWE-89",
      "title": "WordPress WordPress Persistent Login plugin <= 3.1.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66594"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-73998",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axew3",
      "product": "WP w3all phpBB",
      "cwe": "CWE-89",
      "title": "WordPress WP w3all phpBB plugin <= 3.0.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73998"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-74013",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress.com",
      "product": "eShipper Commerce",
      "cwe": "CWE-89",
      "title": "WordPress eShipper Commerce plugin <= 2.16.13 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74013"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-75860",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00341,
      "epss_percentile": 0.26672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JSON Options",
      "cwe": "CWE-269",
      "title": "JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75860"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-53569",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.26581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-862",
      "title": "Frappe: Missing authorization in toggle_like and mark_as_seen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53569"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-18301",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18301"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-18306",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18306"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-18308",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18308"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-18309",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18309"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-54770",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.26399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pylons",
      "product": "webob",
      "cwe": "CWE-601",
      "title": "WebOb: Open redirect in Location header normalization via leading C0 control / space characters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54770"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-64970",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.25987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-79",
      "title": "Stored XSS in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64970"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-76641",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.25871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat",
      "product": "libexpat",
      "cwe": "CWE-125",
      "title": "Expat Out-of-Bounds Read via dtdCopy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76641"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-46682",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.25685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bigbluebutton",
      "product": "bigbluebutton",
      "cwe": "CWE-89",
      "title": "BigBlueButton: Blind SQL Injection AUTH (Moderator)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46682"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-66586",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.25661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themewinter",
      "product": "WP Cafe Pro",
      "cwe": "CWE-98",
      "title": "WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66586"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-18300",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.25527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18300"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2025-15689",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.25417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Capella",
      "cwe": "CWE-266",
      "title": "WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15689"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-66682",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.25416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tyche Softwares.",
      "product": "Abandoned Cart Pro for WooCommerce",
      "cwe": "CWE-266",
      "title": "WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66682"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-69543",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.2519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Virtual Machines",
      "cwe": "CWE-918",
      "title": "Azure Virtual Machines Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69543"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-53585",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.2524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libgit2",
      "product": "libgit2",
      "cwe": "CWE-770",
      "title": "libgit2: Unbounded Memory Allocation via Delta Object Result-Size Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53585"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-76764",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-74",
      "title": "code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76764"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-53584",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libgit2",
      "product": "libgit2",
      "cwe": "CWE-22",
      "title": "libgit2: Submodule path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53584"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-17003",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17003"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-71492",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.24583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masci",
      "product": "banks",
      "cwe": "CWE-22",
      "title": "Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71492"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-67567",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00322,
      "epss_percentile": 0.24417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-441",
      "title": "Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67567"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-76564",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Cart extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76564"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-76565",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Cart extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76565"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-16928",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-122",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16928"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-54616",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.2414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-125",
      "title": "NanaZip: Heap out-of-bounds read in NanaZip SquashFS LZ4 decompressor via unchecked negative return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54616"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-16926",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.2354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-73",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16926"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-77084",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-78",
      "title": "n8n before 1.123.69 Remote Code Execution via Git Node Configuration Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77084"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-16924",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-191",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16924"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-77644",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.23513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PTC",
      "product": "Windchill Risk and Reliability Enterprise Edition (Formerly Relex)",
      "cwe": "CWE-306",
      "title": "Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77644"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-54508",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.23498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-918",
      "title": "TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54508"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-18271",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenwood",
      "product": "DNR1007XR",
      "cwe": "CWE-122",
      "title": "Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18271"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-76987",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.2276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liftoff-sr",
      "product": "CIPster",
      "cwe": "CWE-119",
      "title": "liftoff-sr CIPster Generic Attribute Logic ciptypes.h SetAttrData memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76987"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-54509",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.22465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-862",
      "title": "TREK IDOR: any authenticated user can read another user's journey share token (full journey leak)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54509"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-61625",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VictoriaMetrics",
      "product": "VictoriaMetrics",
      "cwe": "CWE-22",
      "title": "VictoriaMetrics vmrestore: path traversal via crafted backup part names escapes restore root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61625"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-65842",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "udecode",
      "product": "plate",
      "cwe": "CWE-918",
      "title": "Plate: SSRF with response disclosure in DOCX image embedding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65842"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-18281",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.21921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "XAV-9500ES",
      "cwe": "CWE-122",
      "title": "Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18281"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-18282",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.21921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "XAV-9500ES",
      "cwe": "CWE-122",
      "title": "Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18282"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-77075",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.21718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-94",
      "title": "n8n before 1.123.69 Expression Injection via Resource Locator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77075"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-73199",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.2169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73199"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-77151",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.21614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lin-snow",
      "product": "Ech0",
      "cwe": "CWE-327",
      "title": "lin-snow Ech0 crypto.go MD5Encrypt risky encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77151"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-77073",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 2.34.1 Cross-Project Credential Access via MCP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77073"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-77081",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.21601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 1.123.69 Allowed-Domains Bypass via GraphQL Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77081"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-64972",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.21454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-79",
      "title": "Reflected XSS in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64972"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-76634",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.2139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LabRedesCefetRJ",
      "product": "WeGIA",
      "cwe": "CWE-639",
      "title": "WeGIA < 3.9.2 Insecure Direct Object Reference via profile_funcionario.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76634"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-64968",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64968"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-66788",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00293,
      "epss_percentile": 0.21268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-284",
      "title": "Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66788"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-18267",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenwood",
      "product": "DNR1007XR",
      "cwe": "CWE-59",
      "title": "Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18267"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-19683",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "ER7212PC v2",
      "cwe": "CWE-319",
      "title": "Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19683"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2025-15688",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Capella",
      "cwe": "CWE-89",
      "title": "WordPress Capella theme <= 2.5.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15688"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-66592",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.2108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtCamp",
      "product": "rtMedia for WordPress, BuddyPress and bbPress",
      "cwe": "CWE-89",
      "title": "WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66592"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-66593",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CleanTalk Inc",
      "product": "Security & Malware scan by CleanTalk",
      "cwe": "CWE-89",
      "title": "WordPress Security & Malware scan by CleanTalk plugin <= 2.184 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66593"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-66609",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodexThemes",
      "product": "TheGem (Elementor)",
      "cwe": "CWE-89",
      "title": "WordPress TheGem (Elementor) theme <= 5.12.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66609"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-66649",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e-plugins",
      "product": "Directory Pro",
      "cwe": "CWE-89",
      "title": "WordPress Directory Pro plugin <= 2.5.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66649"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-66680",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plainware",
      "product": "Locatoraid Store Locator",
      "cwe": "CWE-89",
      "title": "WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66680"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-68566",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.2108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repute Infosystems",
      "product": "BookingPress Appointment Booking Pro",
      "cwe": "CWE-89",
      "title": "WordPress BookingPress Appointment Booking Pro plugin <= 6.0.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68566"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-63016",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-400",
      "title": "Apache InLong: Ordinary users can create new packages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63016"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-19615",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.20976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Admin and Site Enhancements (ASE)",
      "cwe": "CWE-79",
      "title": "Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19615"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-19697",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.20975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GutenKit",
      "cwe": "CWE-79",
      "title": "GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19697"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-74992",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.20976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-79",
      "title": "Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74992"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-55765",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.20783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudnative-pg",
      "product": "cloudnative-pg",
      "cwe": "CWE-256",
      "title": "CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55765"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-64964",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.20709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-340",
      "title": "Generation of Predictable Email Confirmation Token in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64964"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-55095",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.20794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-862",
      "title": "OpenProject: Inplace-edit dialog exposes comments from hidden admin-only project custom fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55095"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-66785",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.20658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-20",
      "title": "Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowedips / ipsec enables traffic hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66785"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-74020",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.20607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anders Norén",
      "product": "Koji",
      "cwe": "CWE-862",
      "title": "WordPress Koji theme <= 2.2.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74020"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-74021",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.20607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anders Norén",
      "product": "Chaplin",
      "cwe": "CWE-862",
      "title": "WordPress Chaplin theme <= 2.6.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74021"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-77076",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.20605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-209",
      "title": "n8n before 1.123.69 Credential Leak via GraphQL Node Error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77076"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-77082",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.20605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1333",
      "title": "n8n before 1.123.69 ReDoS via Filter and Switch Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77082"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-73137",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-200",
      "title": "Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secret exfiltration via helmrelease.repo.secretref.namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73137"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-43678",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.2042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "swift-nio",
      "cwe": "CWE-20",
      "title": "An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43678"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-64965",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-862",
      "title": "Missing Authorization Check in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64965"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-62315",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.19924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-915",
      "title": "Frappe: Mass assignment via set_value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62315"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-75628",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0028,
      "epss_percentile": 0.19881,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Punk-OAuth2",
      "cwe": "CWE-601",
      "title": "Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75628"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-66647",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.19831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "Homlisti",
      "cwe": "CWE-862",
      "title": "WordPress Homlisti theme <= 3.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66647"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-73220",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.19685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cvat-ai",
      "product": "cvat",
      "cwe": "CWE-80",
      "title": "CVAT: Stored XSS via annotation guides in audio tasks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73220"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-62834",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.19402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Data Factory",
      "cwe": "CWE-347",
      "title": "Azure Data Factory Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62834"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-53586",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.19516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libgit2",
      "product": "libgit2",
      "cwe": "CWE-200",
      "title": "libgit2: HTTP transport can leak credentials to an offsite redirect target",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53586"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-13405",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal Addons for Elementor",
      "cwe": "CWE-94",
      "title": "Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13405"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2025-14602",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vsDesk",
      "product": "vsDesk",
      "cwe": "CWE-340",
      "title": "Weak File Name Generation in vsDesk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14602"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-69183",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.1925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "monkeytypegame",
      "product": "monkeytype",
      "cwe": "CWE-290",
      "title": "Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69183"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-17424",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-22",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17424"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-77071",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n before 1.123.69 PostgREST Filter Injection via Supabase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77071"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-17436",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.18787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17436"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-18832",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.18786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18832"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-77083",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.18751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n before 1.123.69 Code Node Sandbox Escape via Function.prototype Pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77083"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-77026",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.18471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tassos.gr",
      "product": "Convert Forms extension for Joomla",
      "cwe": "CWE-602",
      "title": "Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77026"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-73258",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-697",
      "title": "Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73258"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-17153",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siteground",
      "product": "AI Agent by SiteGround",
      "cwe": "CWE-862",
      "title": "AI Agent by SiteGround <= 1.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17153"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-64969",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.17969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-639",
      "title": "Insecure Direct Object Reference in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64969"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-14949",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.17836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-863",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14949"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-76990",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Simple Inventory System",
      "cwe": "CWE-74",
      "title": "code-projects Simple Inventory System delete.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76990"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-76996",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System view_order.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76996"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-76998",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-89",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76998"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-77019",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Apartment Visitor Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Apartment Visitor Management System forgotpw.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77019"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-77020",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Apartment Visitor Management System",
      "cwe": "CWE-89",
      "title": "CodeAstro Apartment Visitor Management System password-recovery.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77020"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-72846",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lightdash",
      "product": "lightdash",
      "cwe": "CWE-918",
      "title": "Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72846"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-55558",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cole",
      "product": "aiosmtplib",
      "cwe": "CWE-74",
      "title": "aiosmtplib: STARTTLS response injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55558"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-63015",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-400",
      "title": "Apache InLong: Non-template responsible persons can view template information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63015"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-50190",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shaarli",
      "product": "Shaarli",
      "cwe": "CWE-79",
      "title": "Shaarli vulnerable to stored XSS via raw bookmark title in document <title> element on public permalink page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50190"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-76569",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Download extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76569"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-76999",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.16944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "CET Automated Grading System with AI Predictive Analytics",
      "cwe": "CWE-266",
      "title": "SourceCodester CET Automated Grading System with AI Predictive Analytics index.php add_grade improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76999"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-62945",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.1687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-639",
      "title": "TREK: Cross-trip reservation title disclosure via file links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62945"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-49436",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.16781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovah",
      "product": "LinkAce",
      "cwe": "CWE-79",
      "title": "LinkAce vulnerable to stored XSS via 'javascript:' URI in Bulk Link API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49436"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-18286",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.16637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aeon",
      "product": "aeon",
      "cwe": "CWE-94",
      "title": "Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18286"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-76783",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DeDeCMS",
      "cwe": "CWE-74",
      "title": "DeDeCMS advancedsearch.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76783"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-77506",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.1656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Znuny",
      "product": "Znuny",
      "cwe": "CWE-79",
      "title": "Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77506"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-49217",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mailu",
      "product": "Mailu",
      "cwe": "CWE-306",
      "title": "Mailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49217"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-44725",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emqx",
      "product": "emqx",
      "cwe": "CWE-345",
      "title": "EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44725"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-71428",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0025,
      "epss_percentile": 0.16105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unstructured-IO",
      "product": "unstructured",
      "cwe": "CWE-601",
      "title": "unstructured: Server-Side Request Forgery in the URL-based partitioning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71428"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-76956",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat project",
      "product": "libexpat",
      "cwe": "CWE-394",
      "title": "In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76956"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-18287",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.15971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aeon",
      "product": "aeon",
      "cwe": "CWE-94",
      "title": "Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18287"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-50192",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.15957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberos-io",
      "product": "agent",
      "cwe": "CWE-200",
      "title": "Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50192"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-16964",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-200",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16964"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-18269",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.15768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenwood",
      "product": "DNR1007XR",
      "cwe": "CWE-787",
      "title": "Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18269"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-77639",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.15652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "torproject",
      "product": "Tor",
      "cwe": "CWE-420",
      "title": "Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77639"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-76633",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LabRedesCefetRJ",
      "product": "WeGIA",
      "cwe": "CWE-620",
      "title": "WeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenha",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76633"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-54624",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-cms",
      "product": "django-cms",
      "cwe": "CWE-285",
      "title": "django CMS: Structure endpoint bypasses page-view permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54624"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-77080",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-78",
      "title": "n8n before 1.123.69 Arbitrary File Read and Write via Snowflake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77080"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-77072",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n before 1.123.69 Stored XSS via Form Completion Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77072"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-66595",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Passionate Programmer Peter",
      "product": "WP Data Access",
      "cwe": "CWE-862",
      "title": "WordPress WP Data Access plugin <= 5.5.80 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66595"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2025-53999",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Altair",
      "cwe": "CWE-862",
      "title": "WordPress Altair theme <= 5.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53999"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-49825",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.1481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxml",
      "product": "lxml",
      "cwe": "CWE-79",
      "title": "lxml: javascript: URL bypass in Cleaner via xlink:href",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49825"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-19448",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.14738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-908",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19448"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-54622",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.14662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-cms",
      "product": "django-cms",
      "cwe": "CWE-639",
      "title": "django CMS: Clipboard copy IDOR discloses unauthorized plugin content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54622"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-63003",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.14662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-cms",
      "product": "django-cms",
      "cwe": "CWE-639",
      "title": "django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63003"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-49996",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00239,
      "epss_percentile": 0.14654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freedomofpress",
      "product": "securedrop-client",
      "cwe": "CWE-601",
      "title": "securedrop-proxy origin limitation can be bypassed with redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49996"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-18297",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.14539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "GStreamer",
      "cwe": "CWE-121",
      "title": "GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18297"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-18298",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.14539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "GStreamer",
      "cwe": "CWE-122",
      "title": "GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18298"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-77070",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-943",
      "title": "n8n before 1.123.69 NoSQL Injection via MongoDB Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77070"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-77113",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Apport",
      "cwe": "CWE-23",
      "title": "Path Traversal Vulnerability in apport-unpack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77113"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-17024",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-295",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17024"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-18294",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OriginLab",
      "product": "Origin Viewer",
      "cwe": "CWE-119",
      "title": "OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18294"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-66001",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.13927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-352",
      "title": "Frappe: Improper Authorization in OAuth2 Consent Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66001"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-16932",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.13824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-78",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16932"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-55013",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.13879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Remote Help",
      "cwe": "CWE-427",
      "title": "Windows Remote Help Defense Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55013"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-77014",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.13886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-197",
      "title": "Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77014"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-75948",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.13606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icagenda.com",
      "product": "iCagenda extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75948"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-73259",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.13605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-79",
      "title": "Mongoose: Reflected XSS via decoded URI in directory listing render",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73259"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-18296",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "GStreamer",
      "cwe": "CWE-122",
      "title": "GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18296"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-77079",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 2.34.1 Authorization Bypass via Custom Role Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77079"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-77085",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n before 2.34.1 SSRF Protection Bypass via SearXNG Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77085"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-77069",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n before 1.123.69 SSRF Protection Bypass via OAuth2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77069"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-64777",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "container",
      "cwe": "CWE-22",
      "title": "A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64777"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-18283",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "XAV-9500ES",
      "cwe": "CWE-285",
      "title": "Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18283"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-76995",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-284",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76995"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-74011",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "revmakx",
      "product": "InfiniteWP Client",
      "cwe": "CWE-89",
      "title": "WordPress InfiniteWP Client plugin <= 1.13.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74011"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-14163",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-532",
      "title": "In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14163"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-76993",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00224,
      "epss_percentile": 0.12852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GreyDGL",
      "product": "PentestGPT",
      "cwe": "CWE-74",
      "title": "GreyDGL PentestGPT Web-Page Crawling injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76993"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-77587",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "torproject",
      "product": "Tor",
      "cwe": "CWE-911",
      "title": "Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77587"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-77067",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnivore-app",
      "product": "omnivore",
      "cwe": "CWE-918",
      "title": "Omnivore Stored Server-Side Request Forgery via the setWebhook Mutation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77067"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-68921",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dicebear",
      "product": "dicebear",
      "cwe": "CWE-79",
      "title": "DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68921"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-73196",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73196"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-52021",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00221,
      "epss_percentile": 0.12409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts, and src/app/api/mobile/search/route.ts components.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52021"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-72860",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-918",
      "title": "9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72860"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-19699",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GutenKit",
      "cwe": "CWE-863",
      "title": "GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19699"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-77640",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00215,
      "epss_percentile": 0.11672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "torproject",
      "product": "Tor",
      "cwe": "CWE-1284",
      "title": "tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77640"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-63043",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-23",
      "title": "Apache InLong: Agent path traversal via unvalidated file source path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63043"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-73253",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00212,
      "epss_percentile": 0.11347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-295",
      "title": "Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73253"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-18295",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "GStreamer",
      "cwe": "CWE-787",
      "title": "GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18295"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-74019",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paulepro2019",
      "product": "EPROLO Dropshipping",
      "cwe": "CWE-862",
      "title": "WordPress EPROLO Dropshipping plugin <= 2.4.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74019"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-66601",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-79",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.39 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66601"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-73402",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hakan Ozevin",
      "product": "WP BASE Booking",
      "cwe": "CWE-79",
      "title": "WordPress WP BASE Booking plugin <= 6.3.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73402"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-46355",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bigbluebutton",
      "product": "bigbluebutton",
      "cwe": "CWE-287",
      "title": "BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46355"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-63037",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00209,
      "epss_percentile": 0.10883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-89",
      "title": "Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63037"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-17060",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.10946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-200",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17060"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-77036",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.10987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elunez",
      "product": "eladmin",
      "cwe": "CWE-266",
      "title": "elunez eladmin GenConfigController improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77036"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-63044",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.10827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-918",
      "title": "Apache InLong: Authenticated SSRF via POST /api/node/testConnection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63044"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-17006",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.10705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17006"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-18299",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.1068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "GStreamer",
      "cwe": "CWE-416",
      "title": "GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18299"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-7485",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.1071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-863",
      "title": "Frozen BI aggregations leak host and service names to unauthorized users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7485"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-69242",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-122",
      "title": "libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69242"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-63038",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00205,
      "epss_percentile": 0.10367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-89",
      "title": "Apache InLong: SQL Injection via String Concatenation Vulnerability Report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63038"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-77074",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-94",
      "title": "n8n before 1.123.69 SSRF via Edit Image Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77074"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-18288",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OriginLab",
      "product": "OriginPro",
      "cwe": "CWE-787",
      "title": "OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18288"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-18289",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OriginLab",
      "product": "OriginPro",
      "cwe": "CWE-787",
      "title": "OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18289"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-18290",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OriginLab",
      "product": "OriginPro",
      "cwe": "CWE-787",
      "title": "OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18290"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-18291",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OriginLab",
      "product": "OriginPro",
      "cwe": "CWE-119",
      "title": "OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18291"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-18292",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OriginLab",
      "product": "OriginPro",
      "cwe": "CWE-119",
      "title": "OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18292"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-18293",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OriginLab",
      "product": "Origin Viewer",
      "cwe": "CWE-787",
      "title": "OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18293"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-16958",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16958"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-76800",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.09942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DeDeCMS",
      "cwe": "CWE-284",
      "title": "DeDeCMS select_media_post.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76800"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-11861",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.09826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-266",
      "title": "Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11861"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-72861",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.09726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appwrite",
      "product": "templates",
      "cwe": "CWE-347",
      "title": "Appwrite Templates github-issue-bot Skips Webhook Signature Verification When the X-Hub-Signature-256 Header Is Absent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72861"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-18828",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.09815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18828"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-49245",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "drakkan",
      "product": "sftpgo",
      "cwe": "CWE-79",
      "title": "SFTPGo: Stored XSS via inline parameter on public shares and user file download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49245"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-76785",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amirsanni",
      "product": "Mini-Inventory-and-Sales-Management-System",
      "cwe": "CWE-74",
      "title": "amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76785"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-76991",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-89",
      "title": "itsourcecode Hospital Management System viewappointmentapproved.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76991"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-76997",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-89",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php save_category sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76997"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-77025",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewappointmentpending.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77025"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-77066",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnivore-app",
      "product": "omnivore",
      "cwe": "CWE-918",
      "title": "Omnivore Server-Side Request Forgery via the scanFeeds GraphQL Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77066"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-61663",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-cms",
      "product": "django-cms",
      "cwe": "CWE-639",
      "title": "django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61663"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-14953",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-425",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to improper enforcement of role-based access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14953"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-18280",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.0946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "XAV-9500ES",
      "cwe": "CWE-120",
      "title": "Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18280"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-73251",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00195,
      "epss_percentile": 0.0925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-295",
      "title": "Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73251"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-77642",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "torproject",
      "product": "Tor",
      "cwe": "CWE-787",
      "title": "tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77642"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-77641",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "torproject",
      "product": "Tor",
      "cwe": "CWE-252",
      "title": "tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. This is TROVE-2026-017.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77641"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-55489",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bigbluebutton",
      "product": "bigbluebutton",
      "cwe": "CWE-639",
      "title": "BigBlueButton: IDOR on BBB through /api/graphql via POST parameter \"presentationId\" leads to Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55489"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-53583",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.08818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libgit2",
      "product": "libgit2",
      "cwe": "CWE-295",
      "title": "libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53583"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-77648",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.08821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Glance",
      "cwe": "CWE-918",
      "title": "In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77648"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-63039",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00191,
      "epss_percentile": 0.08752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-89",
      "title": "Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63039"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-73254",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.08753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesanta",
      "product": "mongoose",
      "cwe": "CWE-79",
      "title": "Mongoose: Stored XSS via unescaped filenames in directory listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73254"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-63040",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-552",
      "title": "Apache InLong: Missing authorization in StreamSource forceDelete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63040"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-9033",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "ER7212PC v2",
      "cwe": "CWE-306",
      "title": "Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9033"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-15743",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00184,
      "epss_percentile": 0.07995,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Catalyst-Plugin-Static-Simple",
      "cwe": "CWE-524",
      "title": "Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15743"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-72844",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leanprover",
      "product": "lean4",
      "cwe": "CWE-843",
      "title": "Lean 4 Kernel Type Checking Bypass via Mismatched Structure Projections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72844"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2025-62307",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "IEM",
      "cwe": "CWE-778",
      "title": "HCL IntelliOps Event Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62307"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-66581",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.14.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66581"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-66582",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "TranslatePress",
      "cwe": "CWE-79",
      "title": "WordPress TranslatePress plugin <= 3.3.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66582"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-66590",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tagembed",
      "product": "Tagembed",
      "cwe": "CWE-79",
      "title": "WordPress Tagembed plugin <= 7.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66590"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-66597",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melograno Venture Studio",
      "product": "wpDataTables",
      "cwe": "CWE-79",
      "title": "WordPress wpDataTables plugin <= 6.5.1.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66597"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-66598",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kingtech LLC.",
      "product": "B2BKing Premium",
      "cwe": "CWE-79",
      "title": "WordPress B2BKing Premium plugin <= 5.6.07 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66598"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-66604",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-79",
      "title": "WordPress GeoDirectory plugin <= 2.8.173 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66604"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-66605",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HasThemes",
      "product": "Swatchly – WooCommerce Variation Swatches for Products",
      "cwe": "CWE-79",
      "title": "WordPress Swatchly – WooCommerce Variation Swatches for Products plugin <= 1.4.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66605"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-66606",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "SmartSMTP",
      "cwe": "CWE-79",
      "title": "WordPress SmartSMTP plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66606"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-66607",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeHunk",
      "product": "Advance Product Search",
      "cwe": "CWE-79",
      "title": "WordPress Advance Product Search plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66607"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-66611",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymob",
      "product": "Paymob for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Paymob for WooCommerce plugin <= 4.1.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66611"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-66612",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thembay",
      "product": "Aora",
      "cwe": "CWE-79",
      "title": "WordPress Aora theme <= 1.3.19 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66612"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-66614",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEO Squirrly",
      "product": "SEO Plugin by Squirrly SEO",
      "cwe": "CWE-79",
      "title": "WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66614"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-66615",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eric Teubert",
      "product": "Podlove Podcast Publisher",
      "cwe": "CWE-79",
      "title": "WordPress Podlove Podcast Publisher plugin <= 4.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66615"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-66616",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "Form Maker by 10Web",
      "cwe": "CWE-79",
      "title": "WordPress Form Maker by 10Web plugin <= 1.15.46 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66616"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-66673",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monkeysan",
      "product": "Flatastic",
      "cwe": "CWE-79",
      "title": "WordPress Flatastic theme <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66673"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-68564",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NotificationX",
      "product": "NotificationX Pro",
      "cwe": "CWE-79",
      "title": "WordPress NotificationX Pro plugin <= 3.1.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68564"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-53425",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dropbox",
      "product": "samly",
      "cwe": "CWE-345",
      "title": "Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53425"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-77584",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "torproject",
      "product": "Tor",
      "cwe": "CWE-821",
      "title": "Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77584"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-28163",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "myCred",
      "product": "New User Approve",
      "cwe": "CWE-862",
      "title": "WordPress New User Approve plugin <= 3.2.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28163"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-63654",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-352",
      "title": "Frappe: Unauthenticated Workflow approval via confirm_action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63654"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-64962",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.06999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATutor",
      "product": "ATutor",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) in ATutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64962"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-77638",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.06887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "torproject",
      "product": "Tor",
      "cwe": "CWE-362",
      "title": "Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77638"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-66787",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-345",
      "title": "Lighthouse: lighthouse: cross-cluster dns spoofing via unvalidated endpointslice and serviceimport ips",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66787"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-19582",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Migration Toolkit for Containers",
      "cwe": "CWE-787",
      "title": "Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19582"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-63042",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-552",
      "title": "Apache InLong: Missing authorization on DataNode management endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63042"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-15679",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hugging Face",
      "product": "PyTorch Image Models",
      "cwe": "CWE-502",
      "title": "Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15679"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2025-62306",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.05991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "IEM",
      "cwe": "CWE-221",
      "title": "HCL IntelliOps Event Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62306"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-18278",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.05997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "XAV-9500ES",
      "cwe": "CWE-125",
      "title": "Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18278"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2025-52182",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.05996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52182"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-14951",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.05928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frauscher Sensortechnik",
      "product": "FDS 102",
      "cwe": "CWE-352",
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Cross-Site Request Forgery due to missing CSFR protection headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14951"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-55491",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.05947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bigbluebutton",
      "product": "bigbluebutton",
      "cwe": "CWE-79",
      "title": "BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55491"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-75526",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.05861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-cms",
      "product": "django-cms",
      "cwe": "CWE-79",
      "title": "django CMS: Stored XSS in edit-mode plugin exception rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75526"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-71368",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkingreed Inc.",
      "product": "F-RevoCRM",
      "cwe": "CWE-79",
      "title": "F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71368"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2025-62299",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "IEM",
      "cwe": "CWE-272",
      "title": "HCL IntelliOps Event Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62299"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-17423",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17423"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-76610",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76610"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-77643",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xapian",
      "product": "xapian-core",
      "cwe": "CWE-79",
      "title": "A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77643"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-18273",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.04896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenwood",
      "product": "DNR1007XR",
      "cwe": "CWE-276",
      "title": "Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18273"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-70383",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Estonian Information System Authority (RIA)",
      "product": "DigiDoc4",
      "cwe": "CWE-22",
      "title": "Arbitrary file overwrite vulnerability in DigiDoc4 client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70383"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-76833",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cgauge",
      "product": "@cgauge/yaml",
      "cwe": "CWE-95",
      "title": "@cgauge/yaml npm Package Arbitrary Code Execution via eval() YAML Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76833"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2025-62300",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "IEM",
      "cwe": "CWE-362",
      "title": "HCL IntelliOps Event Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62300"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-54625",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "django-cms",
      "product": "django-cms",
      "cwe": "CWE-349",
      "title": "django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54625"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-28164",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00146,
      "epss_percentile": 0.04079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashThemes",
      "product": "Easy Elementor Addons",
      "cwe": "CWE-352",
      "title": "WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28164"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-18716",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18716"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-67448",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-177",
      "title": "Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67448"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-43798",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "swift-nio-ssh",
      "cwe": null,
      "title": "A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43798"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-64773",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.0405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "container",
      "cwe": null,
      "title": "An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64773"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-63388",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-617",
      "title": "Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63388"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-21784",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "IEM",
      "cwe": "CWE-200",
      "title": "HCL IntelliOps Event Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21784"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-72852",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hank-ai",
      "product": "darknet",
      "cwe": "CWE-190",
      "title": "darknet Integer Overflow in Convolutional Layer Buffer Sizing Leads to Heap Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72852"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-55893",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "capstone-engine",
      "product": "capstone",
      "cwe": "CWE-122",
      "title": "Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55893"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-17422",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00135,
      "epss_percentile": 0.03191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17422"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-54389",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NationalSecurityAgency",
      "product": "ghidra",
      "cwe": "CWE-770",
      "title": "Ghidra < 12.1.3 PDB Parser Uncontrolled Heap Growth DoS via AbstractPdb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54389"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-55894",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "capstone-engine",
      "product": "capstone",
      "cwe": "CWE-125",
      "title": "Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55894"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-18263",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Parallels",
      "product": "RAS Client",
      "cwe": "CWE-749",
      "title": "Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18263"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-77118",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.02901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GraphicsMagick Group",
      "product": "GraphicsMagick",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in GraphicsMagick PCD decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77118"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-13121",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.02822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Parallels",
      "product": "RAS Client",
      "cwe": "CWE-749",
      "title": "Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13121"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-18262",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.02821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Parallels",
      "product": "RAS Client",
      "cwe": "CWE-749",
      "title": "Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18262"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-18917",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.02833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18917"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-61898",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.02869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "accountsservice",
      "cwe": "CWE-78",
      "title": "accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61898"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-17171",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-59",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17171"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-16951",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16951"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-18840",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-822",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18840"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-16989",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-59",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16989"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-55586",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sumatrapdfreader",
      "product": "sumatrapdf",
      "cwe": "CWE-119",
      "title": "SumatraPDF: Heap out-of-bounds write in vendored CHMLib LZX Huffman table construction reachable from crafted CHM files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55586"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-19442",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-822",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19442"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-16997",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16997"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-70653",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-122",
      "title": "libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radiance image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70653"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-18842",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18842"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-17124",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17124"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-70651",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-680",
      "title": "libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70651"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-63381",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-908",
      "title": "Libevent: Dangling Pointer in `evbuffer_add_buffer_reference`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63381"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-16943",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16943"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-16944",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16944"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-19783",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19783"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-16936",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.0174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16936"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-16945",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.0174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-121",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16945"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-18270",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenwood",
      "product": "DNR1007XR",
      "cwe": "CWE-732",
      "title": "Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18270"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-16996",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16996"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-70654",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-122",
      "title": "libvips: A well-crafted PPM image processed via a custom source could lead to possible heap buffer write overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70654"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-70652",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00114,
      "epss_percentile": 0.0163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-126",
      "title": "libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG with gain map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70652"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-72854",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "msgpack",
      "product": "msgpack-c",
      "cwe": "CWE-190",
      "title": "msgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized Reservation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72854"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-63380",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libevent",
      "product": "libevent",
      "cwe": "CWE-416",
      "title": "Libevent: Null Pointer Dereference in `evws_new_session`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63380"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-17007",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-125",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17007"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-73542",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEIKO EPSON CORPORATION",
      "product": "Multiple SEIKO EPSON printers and scanners",
      "cwe": "CWE-296",
      "title": "Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73542"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-16973",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-200",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16973"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-18822",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18822"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-16934",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.0122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16934"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-16946",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.0122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16946"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-19755",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NoSleep",
      "product": "NoSleep",
      "cwe": "CWE-862",
      "title": "NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19755"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-72847",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canop",
      "product": "broot",
      "cwe": "CWE-150",
      "title": "broot Terminal Escape Sequence Injection via Unsanitized File and Directory Names in the Tree View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72847"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-76957",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat project",
      "product": "libexpat",
      "cwe": "CWE-416",
      "title": "libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76957"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-19449",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19449"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-16991",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16991"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-17195",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-787",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17195"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-16952",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16952"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-16980",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-59",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16980"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-61897",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "accountsservice",
      "cwe": "CWE-273",
      "title": "accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61897"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-16937",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16937"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-17009",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-476",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17009"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-64846",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00088,
      "epss_percentile": 0.00421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NixOS",
      "product": "nix",
      "cwe": "CWE-61",
      "title": "Nix: Arbitrary file truncation outside the sandbox with recursive-nix experimental feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64846"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-16925",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00086,
      "epss_percentile": 0.00367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-285",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16925"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-16935",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00084,
      "epss_percentile": 0.00293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-367",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16935"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-16927",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00082,
      "epss_percentile": 0.00259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-367",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16927"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-16923",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-269",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16923"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-16922",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00077,
      "epss_percentile": 0.00121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-367",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16922"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-72529",
      "detail": "ADDED TO KEV — CVE-2026-72529 (TrueConf Server). Remediation due August 23, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-72530",
      "detail": "ADDED TO KEV — CVE-2026-72530 (TrueConf Server). Remediation due September 3, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-2586",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-2586 (The Linux Kernel Organization linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59939 (httplib2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61518",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61518 (ispconfig3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64849 (mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75978",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75978 (xianrendzw EasyReport). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75979",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75979 (xianrendzw EasyReport). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76003",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76003 (UTT HiPER 1200GW). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76048",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76048 (SourceCodester Simple Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76049 (SourceCodester Simple Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76576",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76576 (yangzongzhuan RuoYi-Vue). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76582",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76582 (TRENDnet TEW-821DAP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76583",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76583 (TRENDnet TV-IP751WIC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76584 (TRENDnet TV-IP751WIC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76590",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76590 (TRENDnet TEW-755AP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76591",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76591 (TRENDnet TEW-755AP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76760",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76760 (chenhg5 cc-connect). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76761",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76761 (chenhg5 cc-connect). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76886",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76886 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-4996",
      "detail": "RESCORED — CVE-2022-4996 (mruby). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16905",
      "detail": "RESCORED — CVE-2026-16905 (IBM Db2 Mirror for i). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17079",
      "detail": "RESCORED — CVE-2026-17079 (IBM Db2 Mirror for i). CVSS 6.3 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17081",
      "detail": "RESCORED — CVE-2026-17081 (IBM Db2 Mirror for i). CVSS 8.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17175",
      "detail": "RESCORED — CVE-2026-17175 (IBM Db2 Mirror for i). CVSS 7.5 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17179",
      "detail": "RESCORED — CVE-2026-17179 (IBM Db2 Mirror for i). CVSS 8.5 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17181",
      "detail": "RESCORED — CVE-2026-17181 (IBM Db2 Mirror for i). CVSS 9.3 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19550",
      "detail": "RESCORED — CVE-2026-19550 (Red Hat Enterprise Linux 10). CVSS 4.3 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42510",
      "detail": "RESCORED — CVE-2026-42510 (OpenStack Ironic). CVSS 6.6 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47867",
      "detail": "RESCORED — CVE-2026-47867 (VMware Avi Load Balancer). CVSS 8.7 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47869",
      "detail": "RESCORED — CVE-2026-47869 (VMware Avi Load Balancer). CVSS 8.7 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47870",
      "detail": "RESCORED — CVE-2026-47870 (VMware Avi Load Balancer). CVSS 7.1 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54117",
      "detail": "RESCORED — CVE-2026-54117 (Microsoft SQL Server 2025 (CU 6)). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54118",
      "detail": "RESCORED — CVE-2026-54118 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74241",
      "detail": "RESCORED — CVE-2026-74241 (Red Hat OpenShift Update Service). CVSS 4.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74242",
      "detail": "RESCORED — CVE-2026-74242 (Red Hat OpenShift Update Service). CVSS 5.3 → 4.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74243",
      "detail": "RESCORED — CVE-2026-74243 (Red Hat OpenShift Update Service). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74244",
      "detail": "RESCORED — CVE-2026-74244 (Red Hat OpenShift Update Service). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74245",
      "detail": "RESCORED — CVE-2026-74245 (Red Hat OpenShift Update Service). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74247",
      "detail": "RESCORED — CVE-2026-74247 (Red Hat OpenShift Update Service). CVSS 4.2 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76762",
      "detail": "RESCORED — CVE-2026-76762 (code-projects Assessment Management). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-69159",
      "detail": "REJECTED — CVE-2026-69159 (FreeRDP). Record withdrawn by the CNA."
    },
    {
      "type": "DISPUTED",
      "cve_id": "CVE-2026-74234",
      "detail": "DISPUTED — CVE-2026-74234 (Legora). Record marked disputed."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
