{
  "day": "2026-08-23",
  "boundary": "UTC calendar day",
  "published_count": 43,
  "by_severity": {
    "CRITICAL": 4,
    "HIGH": 5,
    "MEDIUM": 15,
    "LOW": 15
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 4,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-78063",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.62203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH22",
      "cwe": "CWE-74",
      "title": "Tenda CH22 editFileName formeditFileName command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78063"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-78141",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.62203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH22",
      "cwe": "CWE-74",
      "title": "Tenda CH22 exeCommand formexeCommand command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78141"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-10053",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00718,
      "epss_percentile": 0.51069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10053"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-78148",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0054,
      "epss_percentile": 0.42961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-476",
      "title": "ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78148"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-78147",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00432,
      "epss_percentile": 0.35815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-20",
      "title": "ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78147"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-78145",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0042,
      "epss_percentile": 0.34725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "CTFd",
      "cwe": "CWE-601",
      "title": "CTFd __init__.py _is_safe_url redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78145"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-78154",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "the-momentum",
      "product": "open-wearables",
      "cwe": "CWE-306",
      "title": "the-momentum open-wearables Public Invitation-Code Redemption Endpoint user_invitation_code.py redeem_invitation_code missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78154"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-8445",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.30813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-79",
      "title": "justhtml before 1.12.0 Sanitizer Bypass via Markdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8445"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-4671",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.29929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-400",
      "title": "justhtml before 1.18.0 Denial of Service via CSS Selector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4671"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-78059",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00354,
      "epss_percentile": 0.28091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Stock Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Stock Management System printOrder.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78059"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-78060",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00354,
      "epss_percentile": 0.28091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Stock Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Stock Management System getOrderReport.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78060"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-7808",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.27821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-20",
      "title": "justhtml before 1.16.0 Multiple Security Issues via Sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7808"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-78055",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00347,
      "epss_percentile": 0.27284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78055"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-5388",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-20",
      "title": "justhtml before 1.15.0 Multiple Security Issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5388"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-78156",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.25652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-122",
      "title": "Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78156"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-78115",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00296,
      "epss_percentile": 0.21603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-266",
      "title": "SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78115"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-78144",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00289,
      "epss_percentile": 0.20879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Barangay Resident Profiling Management System",
      "cwe": "CWE-285",
      "title": "code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78144"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-78062",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.2075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vas3k",
      "product": "TaxHacker",
      "cwe": "CWE-259",
      "title": "vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78062"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-19565",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00283,
      "epss_percentile": 0.20225,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Apache-AppSamurai",
      "cwe": "CWE-341",
      "title": "Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19565"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-9769",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.19743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-674",
      "title": "justhtml before 1.10.0 Denial of Service via deeply nested HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9769"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-78061",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.19405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vas3k",
      "product": "TaxHacker",
      "cwe": "CWE-918",
      "title": "vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78061"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-78054",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78054"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-78155",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00272,
      "epss_percentile": 0.1902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OnGres",
      "product": "StackGres",
      "cwe": "CWE-426",
      "title": "Untrusted Search Path in StackGres",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78155"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-78143",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Barangay Resident Profiling Management System",
      "cwe": "CWE-74",
      "title": "code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78143"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-75922",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00262,
      "epss_percentile": 0.17618,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Reverse-Proxy",
      "cwe": "CWE-93",
      "title": "Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75922"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-78057",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00255,
      "epss_percentile": 0.1672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sambitraj",
      "product": "Student-Management-System",
      "cwe": "CWE-74",
      "title": "sambitraj Student-Management-System Management Mutation sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78057"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-78112",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System Project in PHP",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78112"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-78140",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00244,
      "epss_percentile": 0.1529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "UJCMS",
      "cwe": "CWE-791",
      "title": "Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78140"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-78183",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00229,
      "epss_percentile": 0.1351,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "DBD-Pg",
      "cwe": "CWE-787",
      "title": "DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78183"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-78142",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Barangay Resident Profiling Management System",
      "cwe": "CWE-285",
      "title": "code-projects Barangay Resident Profiling Management System Restore/Delete archived_records.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78142"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-74793",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-79",
      "title": "justhtml before 3.11.0 XSS via selectedcontent projection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74793"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-78056",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sambitraj",
      "product": "Student-Management-System",
      "cwe": "CWE-74",
      "title": "sambitraj Student-Management-System Dashboard sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78056"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-78136",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chirpmyradio",
      "product": "CHIRP",
      "cwe": "CWE-95",
      "title": "chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78136"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-77088",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-79",
      "title": "justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77088"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-5389",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-80",
      "title": "justhtml before 1.13.0 XSS via code fence breakout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5389"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-5751",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-79",
      "title": "justhtml before 1.14.0 Mutation XSS via custom sanitization policies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5751"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-8630",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-79",
      "title": "justhtml before 1.12.0 Mutation XSS via Raw Text Elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8630"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-6827",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EmilStenstrom",
      "product": "justhtml",
      "cwe": "CWE-79",
      "title": "justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6827"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-14853",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WooCommerce Bookings",
      "cwe": "CWE-862",
      "title": "WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14853"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-77003",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Content Mask",
      "cwe": "CWE-269",
      "title": "Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77003"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-77116",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.05901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Brave",
      "cwe": "CWE-639",
      "title": "Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77116"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-13598",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00152,
      "epss_percentile": 0.04577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RestrictMate",
      "cwe": null,
      "title": "RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13598"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-77115",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Brave",
      "cwe": "CWE-79",
      "title": "Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77115"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-5914",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14187",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14187 (Unknown Tutor LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16260",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16260 (Unknown Post Grid, Slider & Carousel Ultimate). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16612",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16612 (Unknown FiboSearch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16738",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16738 (Unknown Conekta Payment Gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18052",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18052 (Unknown ManageWP Worker). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19093",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19093 (Unknown Tutor LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19221 (Unknown Forminator Forms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19222",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19222 (Unknown Forminator Forms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34100",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34100 (guardian language-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34101",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34101 (guardian language-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34102",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34102 (guardian language-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34103",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34103 (guardian language-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34104",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34104 (guardian language-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34105",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34105 (guardian language-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46243",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46243 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46331",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46331 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50656",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50656 (Microsoft Malware Protection Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76789",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76789 (Unknown Slider Hero with Video Background, Animation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76793",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76793 (Unknown Firebase Authentication). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77000",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77000 (Unknown WP Social Media Login). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77001",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77001 (Unknown Social Login & Sharing buttons with Analytics By SoClever). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77002",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77002 (Unknown SmilePass Selfie Login). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77988",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77988 (TRENDnet TEW-823DRU). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78050",
      "detail": "RESCORED — CVE-2026-78050 (Comfast CF-N1-S). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78051",
      "detail": "RESCORED — CVE-2026-78051 (alexta69 MeTube). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-10805",
      "detail": "PATCH SHIPPED — CVE-2026-10805 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 1:1.40.16-21.el8_10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-52902",
      "detail": "PATCH SHIPPED — CVE-2026-52902 (Red Hat Ansible Automation Platform 2.7 for RHEL 10). Fixed in Red Hat Ansible Automation Platform 2.7 for RHEL 10 0:4.8.6-1.el10ap."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-40973",
      "detail": "ENRICHED — CVE-2024-40973 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-23160",
      "detail": "ENRICHED — CVE-2025-23160 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
