{
  "day": "2026-08-21",
  "boundary": "UTC calendar day",
  "published_count": 260,
  "by_severity": {
    "CRITICAL": 38,
    "HIGH": 93,
    "MEDIUM": 89,
    "LOW": 20
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 20,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-77683",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01514,
      "epss_percentile": 0.72541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfast",
      "product": "CF-N1-S",
      "cwe": "CWE-74",
      "title": "Comfast CF-N1-S mbox-config system command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77683"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-61400",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01221,
      "epss_percentile": 0.66383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-77",
      "title": "Apache CloudStack: Get and Run Diagnostics Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61400"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-47827",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01161,
      "epss_percentile": 0.64729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "BOSH CLI",
      "cwe": "CWE-77",
      "title": "CVE-2026-47827 – BOSH CLI Powershell Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47827"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-76156",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00833,
      "epss_percentile": 0.54889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datiphy Inc.",
      "product": "Data Management Center",
      "cwe": "CWE-78",
      "title": "Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76156"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-48749",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00807,
      "epss_percentile": 0.5405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-73",
      "title": "Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48749"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-48752",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00807,
      "epss_percentile": 0.5405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-73",
      "title": "Incus has arbitrary file read+write on host via templates/ symlink in malicious image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48752"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-48750",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00784,
      "epss_percentile": 0.53263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-73",
      "title": "Incus has an arbitrary file write on host via `exec-output` symlink in crafted image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48750"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-77806",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00784,
      "epss_percentile": 0.53281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPIP",
      "product": "SPIP",
      "cwe": "CWE-94",
      "title": "SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77806"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-39909",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00769,
      "epss_percentile": 0.52814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-416",
      "title": "llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39909"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-41451",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00719,
      "epss_percentile": 0.51094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tclahr",
      "product": "uac",
      "cwe": "CWE-78",
      "title": "UAC < 3.3.0 Command Injection via User Substitution in parse_artifact.sh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41451"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-48753",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00709,
      "epss_percentile": 0.50735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-73",
      "title": "Incus has an arbitrary file write via path traversal in S3 multipart upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48753"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-48751",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00703,
      "epss_percentile": 0.50489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-862",
      "title": "Incus has a restricted project bypass leading to arbitrary command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48751"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-49849",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00699,
      "epss_percentile": 0.50336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "4xmen",
      "product": "xshop",
      "cwe": "CWE-434",
      "title": "xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49849"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-41450",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00698,
      "epss_percentile": 0.50286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tclahr",
      "product": "uac",
      "cwe": "CWE-78",
      "title": "UAC < 3.3.0 Command Injection via command_collector.sh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41450"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-61539",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00657,
      "epss_percentile": 0.48699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xorbitsai",
      "product": "inference",
      "cwe": "CWE-95",
      "title": "Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61539"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-77086",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00647,
      "epss_percentile": 0.48245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan before v3.7.4 Path Traversal via packageName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77086"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-41449",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0064,
      "epss_percentile": 0.47908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tclahr",
      "product": "uac",
      "cwe": "CWE-78",
      "title": "UAC < 3.3.0 Command Injection via run_command.sh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41449"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-69502",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00582,
      "epss_percentile": 0.45178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-918",
      "title": "Azure SQL Database Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69502"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-77264",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00568,
      "epss_percentile": 0.44457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "101gen",
      "product": "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code",
      "cwe": "CWE-640",
      "title": "Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77264"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-55168",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00528,
      "epss_percentile": 0.42283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "runtipi",
      "product": "runtipi",
      "cwe": "CWE-59",
      "title": "Runtipi: Authenticated arbitrary file write via backup restore symlink planting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55168"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-76904",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00524,
      "epss_percentile": 0.42081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geotools",
      "product": "geotools",
      "cwe": "CWE-89",
      "title": "GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76904"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-47359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00514,
      "epss_percentile": 0.41428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-78",
      "title": "Apache CloudStack: OS Command Injection due to unsanitized mount command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47359"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-77415",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jsonata-js",
      "product": "jsonata",
      "cwe": "CWE-94",
      "title": "JSONata: Arbitrary Code Execution via crafted JSONata expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77415"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-77751",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.39445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp-stix",
      "cwe": "CWE-22",
      "title": "Path Traversal in MISP Object Template Resolution During STIX Import and Export in misp-stix library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77751"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-63421",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.38464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keystonejs",
      "product": "keystone",
      "cwe": "CWE-20",
      "title": "Keystone: `graphql.maxTake` bypass with negative `take`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63421"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-49360",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataRecce",
      "product": "recce",
      "cwe": "CWE-73",
      "title": "Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49360"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-62675",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnigent-ai",
      "product": "omnigent",
      "cwe": "CWE-94",
      "title": "Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62675"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-34741",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-306",
      "title": "Combodo iTop: Authentication bypass in exec.php allows PHP file execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34741"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-62677",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.3693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnigent-ai",
      "product": "omnigent",
      "cwe": "CWE-22",
      "title": "Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62677"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-48755",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-20",
      "title": "Incus has an argument injection in backup compression algorithm leading to AFW and ACE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48755"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-48769",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-20",
      "title": "Incus has an arbitrary file write on its client due to trusted image hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48769"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-55241",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.3629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bluewave-labs",
      "product": "Checkmate",
      "cwe": "CWE-400",
      "title": "Checkmate: Pre-auth Denial of Service via File Upload on Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55241"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-77649",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.35956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "droundy",
      "product": "internment",
      "cwe": "CWE-506",
      "title": "The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77649"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-77650",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.35957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "droundy",
      "product": "append-only-vec",
      "cwe": "CWE-506",
      "title": "The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77650"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-77651",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.35957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "droundy",
      "product": "arrayref",
      "cwe": "CWE-506",
      "title": "The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77651"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-71493",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00426,
      "epss_percentile": 0.35245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infracost",
      "product": "infracost",
      "cwe": "CWE-22",
      "title": "Infracost: Arbitrary file read via config-template readFile symlink traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71493"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-55185",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00426,
      "epss_percentile": 0.35282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniflux",
      "product": "v2",
      "cwe": "CWE-601",
      "title": "Miniflux 2: Open Redirect Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55185"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-45099",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00423,
      "epss_percentile": 0.3501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gruntwork-io",
      "product": "terragrunt",
      "cwe": "CWE-22",
      "title": "Terragrunt: Arbitrary File Deletion via Malicious Module Manifest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45099"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-63125",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00418,
      "epss_percentile": 0.34554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-59",
      "title": "Incus vulnerable to root RCE via image backup.yaml symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63125"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-76157",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.34527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datiphy Inc.",
      "product": "Data Management Center",
      "cwe": "CWE-306",
      "title": "Datiphy Data Management Center - Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76157"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-74252",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74252"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-70656",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00416,
      "epss_percentile": 0.34391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bluewave-labs",
      "product": "Checkmate",
      "cwe": "CWE-1333",
      "title": "Checkmate: Regular Expression Denial of Service (ReDoS) via User-Controlled Regex in Monitor Advanced Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70656"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-76158",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datiphy Inc.",
      "product": "Data Management Center",
      "cwe": "CWE-73",
      "title": "Datiphy Data Management Center - External Control of File Name or Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76158"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-77815",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.3382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zanllp",
      "product": "infinite-image-browsing",
      "cwe": "CWE-59",
      "title": "Infinite Image Browsing Resolves Paths With normpath, Allowing Symlink Escape From Scanned Directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77815"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-77413",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.33725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jsonata-js",
      "product": "jsonata",
      "cwe": "CWE-94",
      "title": "JSONata: Arbitrary Code Execution via crafted JSONata expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77413"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-77814",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.33735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zanllp",
      "product": "infinite-image-browsing",
      "cwe": "CWE-22",
      "title": "Infinite Image Browsing is_path_trusted Prefix Comparison Omits the Trailing Path Separator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77814"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-75932",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.004,
      "epss_percentile": 0.32845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jet Admin",
      "product": "Jet Admin",
      "cwe": "CWE-862",
      "title": "Jet Admin tenant isolation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75932"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-77087",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.3245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paperclipai",
      "product": "paperclip",
      "cwe": "CWE-862",
      "title": "Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77087"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-54789",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIDC",
      "product": "mod_auth_openidc",
      "cwe": "CWE-125",
      "title": "mod_auth_openidc has out-of-bounds read and write in state cookie parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54789"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-75928",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.31834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brushfire",
      "product": "Online Experience",
      "cwe": "CWE-497",
      "title": "Brushfire unauthenticated information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75928"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-59279",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": "CWE-770",
      "title": "Unbounded persistent session allocation via repeated initialize requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59279"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-64679",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "runatlantis",
      "product": "atlantis",
      "cwe": "CWE-22",
      "title": "Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64679"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-63462",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.30695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unleash",
      "product": "unleash",
      "cwe": "CWE-674",
      "title": "Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63462"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-50112",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-78",
      "title": "Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50112"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-16323",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FuyaWeb Internet and Informatics Services",
      "product": "ArchitectPanel Web Admin Panel",
      "cwe": "CWE-698",
      "title": "Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16323"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-59323",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.29884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Spring",
      "cwe": "CWE-770",
      "title": "Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59323"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-77811",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.29827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amazon OpenSearch Service",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77811"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-77761",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.29749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp-stix",
      "cwe": "CWE-459",
      "title": "Cross-Document Parser State Contamination in misp-stix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77761"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-62283",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.2958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-639",
      "title": "Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62283"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-75501",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00368,
      "epss_percentile": 0.29486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Calix",
      "product": "GS7 XGS (GS5239XG)",
      "cwe": null,
      "title": "CVE-2026-75501",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75501"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-71494",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00367,
      "epss_percentile": 0.2933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infracost",
      "product": "infracost",
      "cwe": "CWE-522",
      "title": "Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71494"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-77775",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.28966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Headroom Labs",
      "product": "Headroom",
      "cwe": "CWE-918",
      "title": "Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77775"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-77767",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.28827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reconmap",
      "product": "reconmap",
      "cwe": "CWE-862",
      "title": "Reconmap Report Preview Endpoint Is Marked AllowAnonymous, Exposing Every Project and Client Organisation Without Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77767"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-62960",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.28798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "git-for-windows",
      "product": "git",
      "cwe": "CWE-200",
      "title": "Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62960"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-48050",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.28462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Basekick-Labs",
      "product": "arc",
      "cwe": "CWE-200",
      "title": "Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48050"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-50290",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "asymmetric-effort",
      "product": "specifyjs",
      "cwe": "CWE-79",
      "title": "@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50290"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-76905",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkin",
      "product": "kin-openapi",
      "cwe": "CWE-476",
      "title": "kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76905"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-71862",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.27923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bluewave-labs",
      "product": "Checkmate",
      "cwe": "CWE-200",
      "title": "Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is Enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71862"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-77810",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.2731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Athena Federated Query Neptune Connector",
      "cwe": "CWE-95",
      "title": "Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77810"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-77414",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jsonata-js",
      "product": "jsonata",
      "cwe": "CWE-94",
      "title": "JSONata: Arbitrary Code Execution via crafted JSONata expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77414"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-76612",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.2728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76612"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-53528",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perber",
      "product": "leafwiki",
      "cwe": "CWE-23",
      "title": "FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53528"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-77776",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Headroom Labs",
      "product": "Headroom",
      "cwe": "CWE-639",
      "title": "Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77776"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-62674",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00343,
      "epss_percentile": 0.26844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnigent-ai",
      "product": "omnigent",
      "cwe": "CWE-94",
      "title": "Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62674"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-69228",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.26791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-306",
      "title": "missing authentication vulnerability in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69228"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-67362",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.26375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-601",
      "title": "Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67362"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-73267",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.2583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-602",
      "title": "Clusterclaims-controller: clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no ownership check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73267"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-76611",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.25485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76611"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-69224",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.25386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-200",
      "title": "information disclosure vulnerability in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69224"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-69225",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.25387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-200",
      "title": "information disclosure vulnerability in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69225"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-77763",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.24795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juicedata",
      "product": "juicefs",
      "cwe": "CWE-22",
      "title": "JuiceFS Local Filestore Backend Joins Object Keys onto the Storage Root Without a Containment Check, Allowing Writes Outside the Configured Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77763"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-50538",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LibVNC",
      "product": "libvncserver",
      "cwe": "CWE-122",
      "title": "libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50538"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-77759",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77759"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-18781",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Drag and Drop Multiple File Upload for Contact Form 7",
      "cwe": "CWE-94",
      "title": "Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18781"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-53572",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kedacore",
      "product": "keda",
      "cwe": "CWE-74",
      "title": "KEDA: PostgreSQL connection string parameter injection via incomplete whitespace escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53572"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-62316",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.23752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-200",
      "title": "Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62316"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-55850",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.23658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "element-hq",
      "product": "element-web",
      "cwe": "CWE-79",
      "title": "Element Web: A malicious homeserver can inject HTML in Element Web using its homepage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55850"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-27462",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-204",
      "title": "Combodo iTop: User enumeration via password reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27462"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-27490",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-330",
      "title": "Combodo iTop: Weak secret generation for inline image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27490"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-19441",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.23577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IKAS Technology Inc.",
      "product": "Rush",
      "cwe": "CWE-306",
      "title": "Unauthenticated API Allows Analytics Data Manipulation in IKAS Technology's Rush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19441"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-59989",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.23442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phalcon",
      "product": "cphalcon",
      "cwe": "CWE-94",
      "title": "Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59989"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-75115",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.23444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "YOOtheme Pro extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75115"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-77755",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.22498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp-stix",
      "cwe": "CWE-400",
      "title": "Denial of Service in MISP-STIX Import via Malformed or Oversized STIX Documents in misp-stix library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77755"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-77354",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkin",
      "product": "kin-openapi",
      "cwe": "CWE-400",
      "title": "kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77354"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-75933",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.21791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jet Admin",
      "product": "Jet Admin",
      "cwe": "CWE-79",
      "title": "Jet Admin Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75933"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-62676",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.21436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnigent-ai",
      "product": "omnigent",
      "cwe": "CWE-184",
      "title": "Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62676"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-54457",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tensorzero",
      "product": "tensorzero",
      "cwe": "CWE-552",
      "title": "TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54457"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-47735",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Basekick-Labs",
      "product": "arc",
      "cwe": "CWE-22",
      "title": "Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47735"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-76613",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "YOOtheme Pro extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76613"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-76155",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.2111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datiphy Inc.",
      "product": "Data Management Center",
      "cwe": "CWE-1392",
      "title": "Datiphy Data Management Center - Use of Default Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76155"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-77710",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "misp-stix",
      "cwe": "CWE-20",
      "title": "STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77710"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-62867",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.2077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-88",
      "title": "Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62867"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-63046",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.20728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache InLong",
      "cwe": "CWE-88",
      "title": "Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63046"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-17251",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.20759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR6400 v7.0",
      "cwe": "CWE-476",
      "title": "Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Request Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17251"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-76876",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "puemos",
      "product": "craftplan",
      "cwe": "CWE-862",
      "title": "Craftplan < 0.5.1 Broken Access Control Information Disclosure via Settings API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76876"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-34836",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.19921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-862",
      "title": "Combodo iTop: Improper access control in ajax.render.php and ajax.document.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34836"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-50288",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.19501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "asymmetric-effort",
      "product": "specifyjs",
      "cwe": "CWE-918",
      "title": "@asymmetric-effort/specifyjs: URL parse failure silently allows request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50288"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-22681",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.1948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Volcengine",
      "product": "OpenViking",
      "cwe": "CWE-918",
      "title": "OpenViking < 0.3.4 SSRF via /api/v1/resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22681"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-63004",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unleash",
      "product": "unleash",
      "cwe": "CWE-918",
      "title": "Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63004"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-77686",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00274,
      "epss_percentile": 0.1928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Dolibarr",
      "cwe": "CWE-266",
      "title": "Dolibarr Account card.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77686"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-30866",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.18768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-200",
      "title": "Combodo iTop: Insecured access to uploaded images via sniffed url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30866"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-77681",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.18654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Online Job Portal",
      "cwe": "CWE-284",
      "title": "CodeAstro Online Job Portal update-profile.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77681"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-33240",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.18567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in foreign key search criteria",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33240"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-15576",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.18571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-306",
      "title": "Agent receiver accepts mTLS requests without a client certificate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15576"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-53524",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.1843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weechat",
      "product": "weechat",
      "cwe": "CWE-409",
      "title": "WeeChat has a Decompression Bomb in Relay WebSocket (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53524"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-63343",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00267,
      "epss_percentile": 0.18318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-73",
      "title": "Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63343"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-31936",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-862",
      "title": "Combodo iTop: Unauthorized access to object information via search operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31936"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-67359",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.17529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67359"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-75796",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.17578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Engine",
      "cwe": "CWE-269",
      "title": "AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75796"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-16576",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution",
      "cwe": "CWE-284",
      "title": "Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16576"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-53531",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.16959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "erweixin",
      "product": "RaTeX",
      "cwe": "CWE-400",
      "title": "ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53531"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-30819",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.16781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30819"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-17559",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.16733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Passster",
      "cwe": "CWE-863",
      "title": "Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17559"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-53525",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.16556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weechat",
      "product": "weechat",
      "cwe": "CWE-208",
      "title": "WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53525"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-53530",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "erweixin",
      "product": "RaTeX",
      "cwe": "CWE-248",
      "title": "ratex-parser panics on `\\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53530"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-77780",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77780"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-68508",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facebookresearch",
      "product": "hydra",
      "cwe": "CWE-94",
      "title": "Hydra: hydra.utils.instantiate with untrusted config can lead to code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68508"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-27463",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-200",
      "title": "Combodo iTop: Version disclosure via login page logo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27463"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-77392",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Dynamic Input Field Generator Using HTML, CSS, and PHP",
      "cwe": "CWE-74",
      "title": "SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77392"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-69233",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.15893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "stored cross site scripting issue in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69233"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-63135",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.15764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YOURLS",
      "product": "YOURLS",
      "cwe": "CWE-79",
      "title": "YOURLS: Stored XSS in referrer statistics chart via crafted Referer header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63135"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-50278",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.15748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternationalColorConsortium",
      "product": "iccDEV",
      "cwe": "CWE-125",
      "title": "iccDEV: CIccEmbedIO::Read8() size_t underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50278"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-62941",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.15665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-863",
      "title": "Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62941"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-53527",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perber",
      "product": "leafwiki",
      "cwe": "CWE-269",
      "title": "LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53527"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-77028",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77028"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-77768",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-639",
      "title": "OpenPanel report.get Returns Any Report by Identifier Without Checking Project Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77768"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-77769",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-639",
      "title": "OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization Boundaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77769"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-53529",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perber",
      "product": "leafwiki",
      "cwe": "CWE-79",
      "title": "LeafWiki vulnerable to stored XSS via search-result title (highlight() returns raw title into dangerouslySetInnerHTML)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53529"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-77220",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.14755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "michaelrsweet",
      "product": "pdfio",
      "cwe": "CWE-825",
      "title": "PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77220"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-67360",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.14775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67360"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-69231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.14633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "stored cross site scripting issue in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69231"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-69232",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.14633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "stored cross site scripting issue in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69232"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-13736",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.14628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "NewPath WildApricotPress Add-on",
      "cwe": "CWE-284",
      "title": "NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13736"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-77781",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00238,
      "epss_percentile": 0.14552,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Tie-Hash-Regex",
      "cwe": "CWE-248",
      "title": "Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77781"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-13176",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-918",
      "title": "Eventin < 4.1.21 - Contributor+ Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13176"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-69234",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "reflected cross site scripting vulnerability in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69234"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-30826",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in run_query.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30826"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-30890",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in synchro/synchro_import.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30890"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-31803",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in tag admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31803"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-31880",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in universal search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31880"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-53497",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cenodude",
      "product": "CrossWatch",
      "cwe": "CWE-200",
      "title": "CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53497"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-62940",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.13863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-862",
      "title": "Incus has a project restriction bypass via instance migration config override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62940"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-18409",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.13769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPForms",
      "product": "WPForms Pro",
      "cwe": "CWE-79",
      "title": "WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18409"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-14601",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.13661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Link Whisper Free",
      "cwe": "CWE-89",
      "title": "Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14601"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-16959",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.13661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Media Library Assistant",
      "cwe": "CWE-89",
      "title": "Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16959"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-61824",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kepano",
      "product": "defuddle",
      "cwe": "CWE-79",
      "title": "Defuddle: XSS via unescaped attribute interpolation in site extractors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61824"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-53541",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OliveTin",
      "product": "OliveTin",
      "cwe": "CWE-20",
      "title": "OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53541"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-34948",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-200",
      "title": "Combodo iTop: Access control bypass via OQL joins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34948"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-59654",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-772",
      "title": "Apache CloudStack: DoS caused by database connections leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59654"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-48754",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-476",
      "title": "Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48754"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-48756",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-476",
      "title": "Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48756"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-19848",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.12657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfilePress",
      "cwe": "CWE-74",
      "title": "ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Display Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19848"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-69229",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.12633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "HTML injection vulnerability in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69229"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-34949",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-306",
      "title": "Combodo iTop: Unauthenticated user can delete .readonly file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34949"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-33047",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-862",
      "title": "Combodo iTop: Object can be locked by a user without write permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33047"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-53509",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.11902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ondata",
      "product": "ckan-mcp-server",
      "cwe": "CWE-918",
      "title": "@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53509"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-62313",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-863",
      "title": "Incus: Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62313"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-54134",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OctoPrint",
      "product": "OctoPrint",
      "cwe": "CWE-73",
      "title": "OctoPrint: File exfiltration possible via query parameters on upload endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54134"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-20679",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-125",
      "title": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20679"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-16575",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.1057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution",
      "cwe": "CWE-200",
      "title": "Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16575"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-55621",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.09881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-284",
      "title": "Incus has a project restriction bypass for custom volume copy across projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55621"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-55622",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.09881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-284",
      "title": "Incus has a project restriction bypass in instance copy across projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55622"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-77795",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.09945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "RuoYi-Vue-Plus",
      "cwe": "CWE-266",
      "title": "Dromara RuoYi-Vue-Plus Workflow Endpoint TestLeaveController improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77795"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-76131",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yamaha Corporation",
      "product": "VOCALOID6",
      "cwe": "CWE-798",
      "title": "Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76131"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-18356",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Limit Login Attempts Security",
      "cwe": "CWE-184",
      "title": "Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Account Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18356"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-59296",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Spring Micrometer",
      "cwe": "CWE-74",
      "title": "Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59296"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-33333",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.09461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-209",
      "title": "Combodo iTop: Information disclosure in ajax.render.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33333"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-69230",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "stored cross site scripting issue in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69230"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-69237",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "HTML injection vulnerability in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69237"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-74866",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/busboy",
      "product": "@fastify/busboy",
      "cwe": "CWE-93",
      "title": "@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74866"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-19435",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00193,
      "epss_percentile": 0.08937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Duplicate Post",
      "cwe": "CWE-200",
      "title": "Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19435"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-17250",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.0887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR6400 v7.0",
      "cwe": "CWE-121",
      "title": "Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17250"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-15580",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "N-able",
      "product": "PassPortal",
      "cwe": "CWE-1385",
      "title": "PassPortal browser extension: vault token disclosure via unvalidated postMessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15580"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-30865",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in dashboard save",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30865"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-73537",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Japan Science and Technology Agency (JST)",
      "product": "Miraikan Assist App Android version",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running on the affected product, resulting in the displayed content being altered.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73537"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-43980",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.07963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zenitraM",
      "product": "malla",
      "cwe": "CWE-79",
      "title": "Malla: Stored XSS via Meshtastic node names in multiple frontend pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43980"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-63466",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unleash",
      "product": "unleash",
      "cwe": "CWE-116",
      "title": "Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63466"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-19085",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00183,
      "epss_percentile": 0.07865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Duplicate Post",
      "cwe": "CWE-639",
      "title": "Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19085"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-59799",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.07723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-269",
      "title": "Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59799"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-16962",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tamara Checkout",
      "cwe": "CWE-862",
      "title": "Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16962"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-44517",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containers",
      "product": "buildah",
      "cwe": "CWE-22",
      "title": "Buildah: Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44517"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-65644",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.07612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rocket.Chat",
      "product": "Rocket.Chat",
      "cwe": "CWE-79",
      "title": "Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65644"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-77391",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Dynamic Input Field Generator Using HTML, CSS, and PHP",
      "cwe": "CWE-352",
      "title": "SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77391"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-69235",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "stored cross site scripting issue in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69235"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-69236",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "stored cross site scripting issue in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69236"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2025-15671",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Welcart e-Commerce",
      "cwe": "CWE-287",
      "title": "Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15671"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-17252",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR6400 v7.0",
      "cwe": "CWE-787",
      "title": "Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17252"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-53487",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kite-org",
      "product": "kite",
      "cwe": "CWE-862",
      "title": "Kite has an authenticated cluster RBAC bypass in /api/v1/overview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53487"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-59780",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0017,
      "epss_percentile": 0.06442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-200",
      "title": "Apache CloudStack: LDAP provider configuration disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59780"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-48105",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Basekick-Labs",
      "product": "arc",
      "cwe": "CWE-22",
      "title": "Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48105"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-59655",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00169,
      "epss_percentile": 0.06391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-200",
      "title": "Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59655"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-61397",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00169,
      "epss_percentile": 0.0639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-200",
      "title": "Apache CloudStack: OAuth2 Token Cross-Request Leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61397"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-59318",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": "CWE-863",
      "title": "DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59318"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-53468",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typemill",
      "product": "typemill",
      "cwe": "CWE-79",
      "title": "Typemill has Stored HTML Attribute Injection in Metadata Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53468"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-16577",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution",
      "cwe": "CWE-863",
      "title": "Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16577"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-47080",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joshnuss",
      "product": "xml_builder",
      "cwe": "CWE-91",
      "title": "CDATA Section Breakout via Unsanitised ]]> in xml_builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47080"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-48590",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joshnuss",
      "product": "xml_builder",
      "cwe": "CWE-91",
      "title": "Element and Attribute Names Injected Verbatim into XML Output in xml_builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48590"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-67361",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.05845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67361"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-74580",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00165,
      "epss_percentile": 0.05903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vhost: reset the vring metadata cache on vring reconfiguration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74580"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-74581",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00165,
      "epss_percentile": 0.05837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ipv6: clear suppressed fib6 rule result",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74581"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-74583",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00165,
      "epss_percentile": 0.05836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_route: fix fastmap use-after-free on filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74583"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-67358",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67358"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-77029",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yootheme.com",
      "product": "Zoo extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77029"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-53499",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NICMx",
      "product": "FORT-validator",
      "cwe": "CWE-346",
      "title": "FORT-validator Vulnerable to RRDP Shared Snapshot Cache Poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53499"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-59308",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": "CWE-668",
      "title": "Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59308"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-48106",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Basekick-Labs",
      "product": "arc",
      "cwe": "CWE-306",
      "title": "Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48106"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-74582",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.04997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "packet: use consistent hard_header_len in non-ring send paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74582"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-45201",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-1284",
      "title": "GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read and/or write of arbitrary physical memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45201"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-45199",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-823",
      "title": "GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45199"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-45202",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-415",
      "title": "GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45202"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-65645",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rocket.Chat",
      "product": "Rocket.Chat",
      "cwe": null,
      "title": "Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {\"$gt\": \"4\"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65645"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-65613",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.03882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-200",
      "title": "Apache CloudStack: Webhook Deliveries Incorrect Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65613"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-59085",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00144,
      "epss_percentile": 0.03882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-918",
      "title": "Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59085"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-14325",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Drag and Drop Multiple File Upload for Contact Form 7",
      "cwe": "CWE-79",
      "title": "Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14325"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-69238",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-79",
      "title": "HTML injection vulnerability in Esri Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69238"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-47079",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joshnuss",
      "product": "xml_builder",
      "cwe": "CWE-838",
      "title": "Round-trip Corruption via Improper Entity Escaping in xml_builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47079"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-47753",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "incus",
      "cwe": "CWE-476",
      "title": "Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47753"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-61399",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.0352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-116",
      "title": "Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61399"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-35163",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OctoPrint",
      "product": "OctoPrint",
      "cwe": "CWE-80",
      "title": "OctoPrint: XSS in Suppressed Command Notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35163"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-61398",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-116",
      "title": "Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61398"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-66797",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-284",
      "title": "Apache CloudStack: Unauthorised comment creation and disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66797"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-54071",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "funstory-ai",
      "product": "BabelDOC",
      "cwe": "CWE-502",
      "title": "BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54071"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-54682",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.0317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tyrrrz",
      "product": "DiscordChatExporter",
      "cwe": "CWE-79",
      "title": "DiscordChatExporter: Stored XSS in HTML export when markdown formatting is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54682"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-61422",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-918",
      "title": "Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61422"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-66722",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-285",
      "title": "Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66722"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-66721",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-862",
      "title": "Apache CloudStack: Authorization issue with listHostTags for domain admins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66721"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-50222",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00132,
      "epss_percentile": 0.02995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-200",
      "title": "Apache CloudStack: Improper access control in Userdata reference APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50222"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-62440",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00132,
      "epss_percentile": 0.0298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-284",
      "title": "Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62440"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-77219",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Emacs",
      "cwe": "CWE-125",
      "title": "GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77219"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-15150",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.0244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "myCred",
      "cwe": "CWE-345",
      "title": "myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15150"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-16650",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.0244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Charitable",
      "cwe": "CWE-345",
      "title": "Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16650"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-54681",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tyrrrz",
      "product": "DiscordChatExporter",
      "cwe": "CWE-79",
      "title": "DiscordChatExporter: HTML attribute injection via unescaped emoji name in HTML export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54681"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-77237",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRTOS",
      "product": "FreeRTOS-Kernel",
      "cwe": "CWE-125",
      "title": "Missing type validation in xQueueAddToSet in FreeRTOS-Kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77237"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-43679",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "watchOS",
      "cwe": "CWE-284",
      "title": "This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43679"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-77234",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00114,
      "epss_percentile": 0.01606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRTOS",
      "product": "FreeRTOS-Kernel",
      "cwe": "CWE-863",
      "title": "Improper input validation in FreeRTOS-Kernel timer command handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77234"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-45271",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "picotls",
      "cwe": "CWE-835",
      "title": "picotls has infinite recursion in the minicrypto ASN.1 decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45271"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-14208",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Remote Utilities Pte. Ltd.",
      "product": "Remote Utilities Host",
      "cwe": "CWE-732",
      "title": "Local Privilege Escalation via Insecure DLL Permissions in Remote Utilities Host <=7.7.3.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14208"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-76137",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yamaha Corporation",
      "product": "VOCALOID6",
      "cwe": "CWE-306",
      "title": "Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76137"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-77236",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRTOS",
      "product": "FreeRTOS-Kernel",
      "cwe": "CWE-787",
      "title": "Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77236"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-49114",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ONNX",
      "product": "ONNX",
      "cwe": "CWE-22",
      "title": "ONNX symlink-following and path-traversal arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49114"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-77235",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRTOS",
      "product": "FreeRTOS-Kernel",
      "cwe": "CWE-416",
      "title": "Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77235"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-59657",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00096,
      "epss_percentile": 0.00771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-312",
      "title": "Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59657"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-15046",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LitExtension",
      "cwe": "CWE-352",
      "title": "LitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeover via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15046"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-53656",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "voxel51",
      "product": "fiftyone",
      "cwe": "CWE-346",
      "title": "FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53656"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-54073",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.0053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veracrypt",
      "product": "VeraCrypt",
      "cwe": "CWE-693",
      "title": "VeraCrypt: Hidden volume quick format weakens plausible deniability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54073"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-68745",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00075,
      "epss_percentile": 0.00088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CloudStack",
      "cwe": "CWE-347",
      "title": "Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68745"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-75946",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.0007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "OMEN Gaming Hub",
      "cwe": "CWE-347",
      "title": "OMEN Gaming Hub – Potential Escalation of Privilege & Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75946"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-27875",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00065,
      "epss_percentile": 0.00018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Simplex Incident Manager / Autocall Fire Administrator",
      "cwe": "CWE-316",
      "title": "Simplex Incident Manager Clear Test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27875"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-77812",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00062,
      "epss_percentile": 0.00009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DJI",
      "product": "Neo",
      "cwe": "CWE-311",
      "title": "Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77812"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-53762",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0006,
      "epss_percentile": 0.00008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veracrypt",
      "product": "VeraCrypt",
      "cwe": "CWE-916",
      "title": "VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-default WOLFCRYPT=1 builds)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53762"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-73570",
      "detail": "ADDED TO KEV — CVE-2026-73570 (Zimbra Collaboration). Remediation due August 24, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20268",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20268 (Zcontent Zap Calendar Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20269",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20269 (Terrywcarter KissGallery). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20270",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20270 (Raindropsinfotech Twitch Tv). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20271",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20271 (Nordmograph StreetGuessr Game). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20273",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20273 (Joomlashowroom Event Registration Pro Calendar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-20275",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-20275 (Henryschorradt Bridge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25754",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25754 (Wdmtech vRestaurant). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25755",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25755 (Wdmtech vReview). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25756",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25756 (Wdmtech vAccount). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25757",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25757 (Wdmtech vWishlist). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25760",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25760 (Joomtech Easy Shop). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25761",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25761 (Joomboost JoomCRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25762",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25762 (Joomboost JoomProject). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-4996",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-4996 (mruby). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-54357",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-54357 (Artio Joomla! com_booking component). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-4598",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0989",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0989 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0990",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0990 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0992",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0992 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19579 (Grokability Snipe-IT). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35091",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35091 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35092",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35092 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3832",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42579 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42584 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53804",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53804 (Centuran Consulting OTRS Community Edition). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59088",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59088 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59089",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59089 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59090",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59090 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59091",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59091 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69414",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72529",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72529 (TrueConf Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72530",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72844",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72844 (leanprover lean4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76764 (code-projects Employee Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76799",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76799 (code-projects Login Registration System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76800",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76800 (DeDeCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76991",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76991 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76997 (SourceCodester Simple Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76998 (SourceCodester Simple Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77020",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77020 (CodeAstro Apartment Visitor Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77022",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77022 (Comfast CF-N1-S). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-62593",
      "detail": "DUE DATE PASSED — CVE-2025-62593 (ray-project ray). CISA remediation deadline was August 20, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-12086",
      "detail": "RESCORED — CVE-2024-12086 (rsync). CVSS 6.1 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-14821",
      "detail": "RESCORED — CVE-2025-14821 (Red Hat Hardened Images). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-32988",
      "detail": "RESCORED — CVE-2025-32988 (libgnutls). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-32990",
      "detail": "RESCORED — CVE-2025-32990 (libgnutls). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-46281",
      "detail": "RESCORED — CVE-2025-46281 (Apple macOS). CVSS 8.4 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-46291",
      "detail": "RESCORED — CVE-2025-46291 (Apple macOS). CVSS 5.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-5372",
      "detail": "RESCORED — CVE-2025-5372 (libssh). CVSS 5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-5916",
      "detail": "RESCORED — CVE-2025-5916 (libarchive). CVSS 3.9 → 5.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-5917",
      "detail": "RESCORED — CVE-2025-5917 (libarchive). CVSS 2.8 → 5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-5918",
      "detail": "RESCORED — CVE-2025-5918 (libarchive). CVSS 3.9 → 6.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0964",
      "detail": "RESCORED — CVE-2026-0964 (Red Hat Enterprise Linux 10). CVSS 5 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0966",
      "detail": "RESCORED — CVE-2026-0966 (Red Hat Enterprise Linux 10). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0967",
      "detail": "RESCORED — CVE-2026-0967 (Red Hat Enterprise Linux 10). CVSS 2.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17186",
      "detail": "RESCORED — CVE-2026-17186 (IBM Db2 Mirror for i). CVSS 9.9 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17209",
      "detail": "RESCORED — CVE-2026-17209 (IBM Db2 Mirror for i). CVSS 6.3 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17227",
      "detail": "RESCORED — CVE-2026-17227 (IBM Db2 Mirror for i). CVSS 5.4 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18178",
      "detail": "RESCORED — CVE-2026-18178 (IBM Db2 Mirror for i). CVSS 5.4 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-3184",
      "detail": "RESCORED — CVE-2026-3184 (Red Hat Hardened Images). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-3441",
      "detail": "RESCORED — CVE-2026-3441 (Red Hat Hardened Images). CVSS 6.1 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-3442",
      "detail": "RESCORED — CVE-2026-3442 (Red Hat Hardened Images). CVSS 6.1 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59090",
      "detail": "RESCORED — CVE-2026-59090 (gimp). CVSS 8.4 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59091",
      "detail": "RESCORED — CVE-2026-59091 (gimp). CVSS 7.3 → 7.8 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
