{
  "day": "2026-08-24",
  "boundary": "UTC calendar day",
  "published_count": 310,
  "by_severity": {
    "CRITICAL": 39,
    "HIGH": 157,
    "MEDIUM": 77,
    "LOW": 14
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 23,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-78211",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01545,
      "epss_percentile": 0.73064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "4MOSAn Security Technology",
      "product": "4MOSAn GCB Doctor",
      "cwe": "CWE-78",
      "title": "4MOSAn Security Technology｜4MOSAn GCB Doctor - OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78211"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-78167",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0103,
      "epss_percentile": 0.61088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EFM",
      "product": "ipTIME T16000M",
      "cwe": "CWE-287",
      "title": "EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78167"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-78168",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00929,
      "epss_percentile": 0.57861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EFM",
      "product": "ipTIME T24000M",
      "cwe": "CWE-287",
      "title": "EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78168"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-59561",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00743,
      "epss_percentile": 0.51931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sakura Editor Development Community",
      "product": "Sakura Editor",
      "cwe": "CWE-78",
      "title": "Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes \"Open Terminal\".",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59561"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-78314",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00655,
      "epss_percentile": 0.48599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-89",
      "title": "DIAEnergie - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78314"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-78315",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00655,
      "epss_percentile": 0.48599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-89",
      "title": "DIAEnergie - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78315"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-78316",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00655,
      "epss_percentile": 0.48599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-89",
      "title": "DIAEnergie - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78316"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-78317",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00655,
      "epss_percentile": 0.48599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-89",
      "title": "DIAEnergie - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78317"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-66897",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00619,
      "epss_percentile": 0.46929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-22",
      "title": "Instance template path traversal allows arbitrary host file write as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66897"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-78177",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00603,
      "epss_percentile": 0.4618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TanStack",
      "product": "devtools-vite",
      "cwe": "CWE-77",
      "title": "TanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78177"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-78212",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "4MOSAn Security Technology",
      "product": "4MOSAn Management Center",
      "cwe": "CWE-23",
      "title": "4MOSAn Security Technology｜4MOSAn Management Center - Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78212"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-78206",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.36935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "exceljs",
      "product": "exceljs",
      "cwe": "CWE-409",
      "title": "exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78206"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-78207",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.3638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "exceljs",
      "product": "exceljs",
      "cwe": "CWE-1321",
      "title": "exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78207"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-78178",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00439,
      "epss_percentile": 0.36368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "jQWidgets",
      "cwe": "CWE-94",
      "title": "jQWidgets jqx-all.js jqxBaseFramework.extend prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78178"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-78180",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00439,
      "epss_percentile": 0.36368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alibaba-fusion",
      "product": "next",
      "cwe": "CWE-94",
      "title": "alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78180"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-78181",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00439,
      "epss_percentile": 0.36368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ractivejs",
      "product": "ractive",
      "cwe": "CWE-94",
      "title": "ractivejs ractive Keypath Ractive#set prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78181"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-78169",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1250GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78169"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-78170",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW formConfigFastDirectionW strcpy buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78170"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-75931",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-436",
      "title": "fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75931"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-78187",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00413,
      "epss_percentile": 0.34145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Piwigo",
      "cwe": "CWE-79",
      "title": "Piwigo Public Authentication cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78187"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-78161",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.3336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warmcat",
      "product": "libwebsockets",
      "cwe": "CWE-119",
      "title": "warmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78161"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-75899",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-174",
      "title": "fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75899"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-75975",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-20",
      "title": "fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75975"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-78186",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0039,
      "epss_percentile": 0.31806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-617",
      "title": "Open5GS HSS hss-cx-path.c assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78186"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-78251",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.3163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DJI",
      "product": "Neo",
      "cwe": "CWE-798",
      "title": "DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78251"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-78208",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.29974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "exceljs",
      "product": "exceljs",
      "cwe": "CWE-73",
      "title": "exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78208"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-19853",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.2591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberTutor",
      "product": "NewSiteServer (NSS)",
      "cwe": "CWE-306",
      "title": "CyberTutor｜NewSiteServer (NSS) - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19853"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-78179",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rexrainbow",
      "product": "phaser3-rex-notes",
      "cwe": "CWE-94",
      "title": "rexrainbow phaser3-rex-notes BehaviorTree Blackboard Data SetValue.js SetValue prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78179"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-78171",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System processlogin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78171"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-78182",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.23487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Gongji Technology",
      "product": "XBROTHER Dynamic Environment Monitoring System",
      "cwe": "CWE-74",
      "title": "Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System plansImmediate PlanController.getImmediatePlans sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78182"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-78213",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hepta Platforms",
      "product": "Heptabase",
      "cwe": "CWE-79",
      "title": "Hepta Platforms｜Heptabase - Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78213"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-78166",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00305,
      "epss_percentile": 0.22574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "provectus",
      "product": "kafka-ui",
      "cwe": "CWE-74",
      "title": "provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78166"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-78205",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bentoml",
      "product": "BentoML",
      "cwe": "CWE-918",
      "title": "BentoML 1.4.19 through 1.4.39 Server-Side Request Forgery via Unfiltered RFC 6598 Shared Address Space",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78205"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-78209",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.21524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "exceljs",
      "product": "exceljs",
      "cwe": "CWE-1236",
      "title": "exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78209"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-78160",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0029,
      "epss_percentile": 0.2095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "ERP",
      "cwe": "CWE-285",
      "title": "Dolibarr ERP User Notes note.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78160"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-78202",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.20749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Payroll System",
      "cwe": "CWE-284",
      "title": "itsourcecode Payroll System admin_class.php save_settings unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78202"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-78203",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.18696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GhostManager",
      "product": "Ghostwriter",
      "cwe": "CWE-639",
      "title": "Ghostwriter before 7.1.2 Cross-Client Report Template Disclosure via Unauthorized Template Swap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78203"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-78197",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.17998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php save_user sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78197"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-78198",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78198"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-78199",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System view_prod.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78199"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-78201",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Payroll System",
      "cwe": "CWE-74",
      "title": "itsourcecode Payroll System admin_class.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78201"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-77993",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlack.fr",
      "product": "Page Builder CK extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77993"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-78200",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Library Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Library Management System editbooks.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78200"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-78185",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System cust_edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78185"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-78255",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.14777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DJI",
      "product": "Neo",
      "cwe": "CWE-306",
      "title": "DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78255"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-19852",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberTutor",
      "product": "NewSiteServer (NSS)",
      "cwe": "CWE-434",
      "title": "CyberTutor｜NewSiteServer (NSS) - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19852"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-77994",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00228,
      "epss_percentile": 0.13307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlack.fr",
      "product": "Page Builder CK extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77994"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-19200",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-94",
      "title": "Velociraptor Analyst overwrites live built-in artifacts through verify()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19200"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-78157",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78157"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-78204",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.12664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GhostManager",
      "product": "Ghostwriter",
      "cwe": "CWE-862",
      "title": "Ghostwriter through 7.2.6 Missing Authorization on Report Template Lint Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78204"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-78158",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.10982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-266",
      "title": "Open5GS AMF UEContextReleaseRequest Path improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78158"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-8173",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Murrelektronik",
      "product": "Xelity 4TX M GE",
      "cwe": "CWE-209",
      "title": "Information Disclosure via 'Copy learned MAC Addresses' Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8173"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-78321",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.05803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DJI",
      "product": "Neo",
      "cwe": "CWE-770",
      "title": "DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78321"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-78306",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.0433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DJI",
      "product": "Neo",
      "cwe": "CWE-306",
      "title": "DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78306"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-78196",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "achorein",
      "product": "expo-share-intent",
      "cwe": "CWE-22",
      "title": "achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt getDataColumn path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78196"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2025-36939",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Nest",
      "cwe": "CWE-121",
      "title": "Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36939"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-77995",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniorange.com",
      "product": "miniOrange OAuth Client extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77995"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-32559",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tophive",
      "product": "UltimateAI",
      "cwe": "CWE-434",
      "title": "WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32559"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-28165",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UnitedOver, LLC",
      "product": "Digits",
      "cwe": "CWE-266",
      "title": "WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28165"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-32558",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RedefiningTheWeb",
      "product": "Affiliate Pro - Affiliate Program for WooCommerce & WordPress",
      "cwe": "CWE-266",
      "title": "WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32558"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-32563",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "A CPT",
      "product": "ACPT (Pro) - Custom Post Types Plugin for WordPress",
      "cwe": "CWE-502",
      "title": "WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32563"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-66587",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPCafe",
      "product": "WP Cafe Pro",
      "cwe": "CWE-98",
      "title": "WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66587"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-66648",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MVPThemes",
      "product": "Jawn",
      "cwe": "CWE-266",
      "title": "WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66648"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-66650",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Theme-Rex",
      "product": "FreightCo",
      "cwe": "CWE-502",
      "title": "WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66650"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-78262",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP Project Manager",
      "cwe": "CWE-502",
      "title": "WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78262"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-78265",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "The Events Calendar",
      "cwe": "CWE-502",
      "title": "WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78265"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-78267",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "TranslatePress",
      "cwe": "CWE-266",
      "title": "WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78267"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-39975",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-94",
      "title": "Combodo iTop: Remote code execution using external auth variable value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39975"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-78387",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-862",
      "title": "RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78387"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-78555",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-200",
      "title": "RansomLook API Key Disclosure Through /admin/apikeys HTML Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78555"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-32551",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DiviNext",
      "product": "Woo Essential",
      "cwe": "CWE-89",
      "title": "WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32551"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-32554",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WBW",
      "product": "WooBeWoo Product Filter Pro",
      "cwe": "CWE-89",
      "title": "WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32554"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-32555",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PixelYourSite Professional",
      "product": "Boost",
      "cwe": "CWE-89",
      "title": "WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32555"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-67602",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpipam",
      "product": "phpipam",
      "cwe": "CWE-706",
      "title": "phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67602"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-71914",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71914"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-71921",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71921"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-76070",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netis Systems",
      "product": "NC63",
      "cwe": "CWE-121",
      "title": "Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76070"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-76071",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netis Systems",
      "product": "NC63",
      "cwe": "CWE-121",
      "title": "Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76071"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-76835",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oauth2-proxy",
      "product": "oauth2-proxy",
      "cwe": "CWE-290",
      "title": "OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy Set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76835"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-77915",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rconfig",
      "product": "rconfig",
      "cwe": "CWE-306",
      "title": "rConfig 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77915"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-78365",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78365"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-77635",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "cakephp",
      "cwe": "CWE-89",
      "title": "CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77635"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-78370",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-862",
      "title": "RansomLook Unauthenticated Database Export Exposes Private Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78370"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-78372",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-862",
      "title": "RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78372"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-19874",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Konami",
      "product": "Metal Gear Online 3",
      "cwe": "CWE-122",
      "title": "Konami's Metal Gear Online 3 contains a heap-based buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19874"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-59564",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-304",
      "title": "Authentication bypass between ZCC and client connector portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59564"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-59568",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-20",
      "title": "Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59568"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-77337",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "authentication",
      "cwe": "CWE-290",
      "title": "CakePHP: Potential Authentication bypass with CookieAuthenticator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77337"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-30864",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-79",
      "title": "Combodo iTop: Reflected XSS in dashboard revert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30864"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2025-36940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-416",
      "title": "Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36940"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-13212",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-129",
      "title": "Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring descriptor id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13212"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-32560",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LiquidThemes",
      "product": "MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator",
      "cwe": "CWE-98",
      "title": "WordPress MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32560"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-32561",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LiquidThemes",
      "product": "Booking Hub",
      "cwe": "CWE-266",
      "title": "WordPress Booking Hub plugin <= 1.3.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32561"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-59565",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-229",
      "title": "Local and kernel denial-of-service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59565"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-59567",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-280",
      "title": "Local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59567"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-71933",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-862",
      "title": "DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71933"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-76842",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mercadopago",
      "product": "mercadopago",
      "cwe": "CWE-22",
      "title": "Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76842"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-78369",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-306",
      "title": "Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78369"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-78376",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-416",
      "title": "Webkitgtk: use-after-free of jscvalue function parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78376"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-78391",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78391"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-78551",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-307",
      "title": "RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication Attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78551"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-9254",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer BE800 V1",
      "cwe": "CWE-78",
      "title": "Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9254"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-40877",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Combodo",
      "product": "iTop",
      "cwe": "CWE-94",
      "title": "Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40877"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-71922",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-476",
      "title": "DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereference via setget.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71922"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-76073",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HumanSignal",
      "product": "label-studio",
      "cwe": "CWE-639",
      "title": "Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationAPI Queryset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76073"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-76836",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AzuraCast",
      "product": "AzuraCast",
      "cwe": "CWE-94",
      "title": "AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76836"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-76841",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xorbitsai",
      "product": "inference",
      "cwe": "CWE-94",
      "title": "Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Model Loaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76841"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-76847",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nektos",
      "product": "act",
      "cwe": "CWE-321",
      "title": "act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76847"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-76848",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typeorm",
      "product": "typeorm",
      "cwe": "CWE-89",
      "title": "TypeORM 0.2.21 through 1.1.0 SQL Injection via SelectQueryBuilder.distinctOn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76848"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-78380",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-862",
      "title": "Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78380"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-78386",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-200",
      "title": "Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78386"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-78416",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-915",
      "title": "Authenticated RCE via `condition.config` JSON cleanse bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78416"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-28171",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vanquish",
      "product": "WooCommerce File Approval",
      "cwe": "CWE-22",
      "title": "WordPress WooCommerce File Approval plugin <= 10.7 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28171"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-32477",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme, LLC",
      "product": "ShopBuilder Pro – Elementor WooCommerce Builder Addons",
      "cwe": "CWE-22",
      "title": "WordPress ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32477"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-71504",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-862",
      "title": "Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71504"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-71904",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via tr069TestInform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71904"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-71905",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via ExportSettings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71905"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-71906",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via setLan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71906"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-71907",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via setcamset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71907"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-71908",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71908"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-71909",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via InquierTime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71909"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-71910",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via apautotest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71910"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-71911",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-120",
      "title": "DrayTek VigorAP Multiple Models Buffer Overflow via setLan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71911"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-71912",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-120",
      "title": "DrayTek VigorAP Multiple Models Buffer Overflow via apautotest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71912"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-71913",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorAP 918R",
      "cwe": "CWE-78",
      "title": "DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71913"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-71915",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71915"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-71916",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via commandTable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71916"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-71917",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via pingtrace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71917"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-71918",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71918"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-71919",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71919"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-71923",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71923"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-71924",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via getVid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71924"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-71925",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71925"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-71926",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71926"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-71927",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71927"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-71928",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71928"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-71929",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71929"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-71930",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via setTime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71930"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-71931",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71931"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-71934",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71934"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-71935",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71935"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-71936",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via sysreboot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71936"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-71937",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71937"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-71938",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71938"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-71939",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add ACE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71939"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-71940",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edit ACE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71940"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-71941",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71941"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-71942",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-120",
      "title": "DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71942"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-71943",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-78",
      "title": "DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71943"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-78284",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "MasterStudy LMS",
      "cwe": "CWE-22",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78284"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2025-63080",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KAON",
      "product": "PG5298A",
      "cwe": "CWE-863",
      "title": "Authenticated RCE in KAON PG5298",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63080"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-12554",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP Easy Start for macOS",
      "cwe": "CWE-1104",
      "title": "HP Easy Start for macOS - Security Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12554"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-16348",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer BE800 v1",
      "cwe": "CWE-78",
      "title": "Command Injection Vulnerability in VPN connection of Archer BE800",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16348"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-32471",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeBing",
      "product": "ProLancer Element",
      "cwe": "CWE-89",
      "title": "WordPress ProLancer Element plugin <= 1.4.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32471"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-32478",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs Pte. Ltd",
      "product": "WP Project Manager Pro",
      "cwe": "CWE-89",
      "title": "WordPress WP Project Manager Pro plugin <= 4.0.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32478"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-39915",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIM Solutions",
      "product": "TIM Flow",
      "cwe": "CWE-113",
      "title": "TIM Flow < 26.0.6 CRLF Injection via rt Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39915"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-76840",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustdesk",
      "product": "rustdesk",
      "cwe": "CWE-20",
      "title": "RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileContentsResponse Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76840"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-78541",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer BE3600 v1",
      "cwe": "CWE-78",
      "title": "Command Injection in Parent Control of TP-Link Archer BE3600 v1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78541"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-59566",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-229",
      "title": "Local denial-of-service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59566"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-76838",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HiEventsDev",
      "product": "Hi.Events",
      "cwe": "CWE-918",
      "title": "Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webhook Redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76838"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-76843",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flairNLP",
      "product": "flair",
      "cwe": "CWE-502",
      "title": "Flair 0.15.0 and 0.15.1 Deserialization of Untrusted Data via ClusteringModel.load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76843"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-10582",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-918",
      "title": "Hugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.urls Lacking Destination Address Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10582"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-75542",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hexpm",
      "product": "hexpm",
      "cwe": "CWE-863",
      "title": "OAuth token exchange grants repository scopes for organizations the principal cannot access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75542"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-76072",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "continuedev",
      "product": "continue",
      "cwe": "CWE-184",
      "title": "Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headless and Auto Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76072"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-76844",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webpack",
      "product": "webpack-dev-middleware",
      "cwe": "CWE-22",
      "title": "webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76844"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-77634",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "cakephp",
      "cwe": "CWE-93",
      "title": "CakePHP: SmtpTransport vulnerable to CRLF header injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77634"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-78381",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-22",
      "title": "RansomLook Arbitrary File Read via Path Traversal in Post screen Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78381"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-78385",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-918",
      "title": "RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local File Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78385"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-28151",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Tonda",
      "cwe": "CWE-98",
      "title": "WordPress Tonda theme < 2.6 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28151"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-28152",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Tonda Core",
      "cwe": "CWE-98",
      "title": "WordPress Tonda Core plugin < 2.6 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28152"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-66670",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Måne",
      "cwe": "CWE-98",
      "title": "WordPress Måne theme <= 1.7 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66670"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-66671",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Verdure Core",
      "cwe": "CWE-98",
      "title": "WordPress Verdure Core plugin <= 1.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66671"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-77567",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-287",
      "title": "Filament: App-based MFA can be bypassed when recovery codes are enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77567"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-78414",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Network Optix",
      "product": "Nx Witness VMS",
      "cwe": "CWE-79",
      "title": "Cross-site scripting in Nx Witness VMS Web Administration allows session token exfiltration via a rogue peer site name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78414"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-7455",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-787",
      "title": "FLT File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7455"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-16783",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-787",
      "title": "ABC File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16783"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-19568",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-120",
      "title": "SVG File Parsing Memory Corruption Vulnerability in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19568"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-61419",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-284",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61419"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-12555",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP Easy Start for macOS",
      "cwe": "CWE-379",
      "title": "HP Easy Start for macOS - Security Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12555"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-12556",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP Easy Start for macOS",
      "cwe": "CWE-319",
      "title": "HP Easy Start for macOS - Security Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12556"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-15469",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Deco XE75 v3 / XE5300  v3.6/ WE10800 v3.6",
      "cwe": "CWE-321",
      "title": "Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15469"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-71366",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-918",
      "title": "Awx: notification backends allow ssrf and credential leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71366"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-78270",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "FluentCRM Pro",
      "cwe": "CWE-89",
      "title": "WordPress FluentCRM Pro plugin <= 3.1.12 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78270"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2025-68825",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Hive",
      "cwe": "CWE-276",
      "title": "HCL Hive is affected by incorrect default permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68825"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-21752",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Hive",
      "cwe": "CWE-1104",
      "title": "HCL Hive is affected by a use of vulnerable third-party components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21752"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-28153",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Notification Master",
      "product": "Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More",
      "cwe": "CWE-862",
      "title": "WordPress Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin <= 1.7.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28153"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-28167",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Super Forms",
      "product": "Super Forms",
      "cwe": "CWE-22",
      "title": "WordPress Super Forms plugin <= 6.3.315 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28167"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-66585",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPCafe",
      "product": "WP Cafe Pro",
      "cwe": "CWE-201",
      "title": "WordPress WP Cafe Pro plugin < 3.0.15 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66585"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-76055",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Duck",
      "product": "blackduck-c-cpp",
      "cwe": "CWE-78",
      "title": "Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned build directory to execute operating system commands as the account running the scan. Filesystem paths encountered while traversing the scanned directory are interpolated into command strings that are executed through a shell without quoting or escaping, so shell metacharacters within those paths are interpreted rather than treated as literal text. No control over the build command or the tool's configuration is required.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76055"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-76098",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-674",
      "title": "Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76098"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-76172",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-177",
      "title": "fast-uri vulnerable to host confusion via percent-encoded scheme normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76172"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-77384",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "js-libp2p",
      "cwe": "CWE-400",
      "title": "libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77384"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-78268",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extend Themes",
      "product": "Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads",
      "cwe": "CWE-497",
      "title": "WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78268"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-21751",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Hive",
      "cwe": "CWE-1240",
      "title": "HCL Hive is affected by use of a cryptographic primitive with a risky implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21751"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-18349",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microchip",
      "product": "SAMA5D4",
      "cwe": "CWE-1247",
      "title": "SAMA5D44 Fault Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18349"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-78259",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Legal Pages",
      "product": "WPLegalPages",
      "cwe": "CWE-288",
      "title": "WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78259"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-21756",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Hive",
      "cwe": "CWE-266",
      "title": "HCL Hive is affected by a broken access control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21756"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-71364",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-22",
      "title": "Awx: project archive extraction allows path traversal file writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71364"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-71506",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-863",
      "title": "Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71506"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-6017",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KAON",
      "product": "PG5298A",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in KAON PG5298",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6017"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-19685",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-863",
      "title": "Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19685"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-28162",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Franky",
      "product": "Events Made Easy",
      "cwe": "CWE-79",
      "title": "WordPress Events Made Easy plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28162"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-28166",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GoodLayers",
      "product": "Tourmaster",
      "cwe": "CWE-79",
      "title": "WordPress Tourmaster plugin <= 5.4.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28166"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-28190",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeBing",
      "product": "ProLancer Element",
      "cwe": "CWE-862",
      "title": "WordPress ProLancer Element plugin <= 1.4.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28190"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-32476",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmpleByte Pvt Limited",
      "product": "Brave Conversion Engine (PRO)",
      "cwe": "CWE-79",
      "title": "WordPress Brave Conversion Engine (PRO) plugin <= 0.8.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32476"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-32556",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PixelYourSite Professional",
      "product": "Boost",
      "cwe": "CWE-79",
      "title": "WordPress Boost plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32556"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-39914",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIM Solutions",
      "product": "TIM Flow",
      "cwe": "CWE-862",
      "title": "TIM Flow < 26.0.6 Unauthorized SQL Query Execution via Dashboard Export Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39914"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-53532",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "openexr",
      "cwe": "CWE-617",
      "title": "OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53532"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-66584",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Code for Recovery",
      "product": "12 Step Meeting List",
      "cwe": "CWE-79",
      "title": "WordPress 12 Step Meeting List plugin <= 3.19.16 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66584"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-66599",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "WPComplete",
      "cwe": "CWE-79",
      "title": "WordPress WPComplete plugin <= 2.9.5.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66599"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-66610",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thembay",
      "product": "Urna",
      "cwe": "CWE-79",
      "title": "WordPress Urna theme <= 2.6.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66610"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-66623",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inisev",
      "product": "Social Media & Share Icons",
      "cwe": "CWE-79",
      "title": "WordPress Social Media & Share Icons plugin <= 2.9.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66623"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-71505",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-639",
      "title": "Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71505"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-71507",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-639",
      "title": "Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71507"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-71508",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-862",
      "title": "Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71508"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-71509",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-862",
      "title": "Dolibarr < 24.0.0 Expense Report REST API Improper Authorization via Update Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71509"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-71510",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-863",
      "title": "Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71510"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-71511",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-522",
      "title": "Dolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71511"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-76054",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Duck",
      "product": "blackduck-c-cpp",
      "cwe": "CWE-214",
      "title": "Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture and signature scanning. This applies only where the token is supplied through the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variable. Upgrading does not remediate prior disclosure; any token supplied to an affected version through an environment variable should be rotated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76054"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-77914",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rconfig",
      "product": "rconfig",
      "cwe": "CWE-22",
      "title": "rConfig < 8.2.13 Core Path Traversal via Export Download Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77914"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-78263",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Event Tickets",
      "cwe": "CWE-79",
      "title": "WordPress Event Tickets plugin <= 5.29.2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78263"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-78264",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Site Building with Toolset",
      "product": "Toolset Blocks",
      "cwe": "CWE-79",
      "title": "WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78264"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-78282",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mra13",
      "product": "Stripe Payments",
      "cwe": "CWE-79",
      "title": "WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78282"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-78367",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-94",
      "title": "Rpm: rpmbuild gettarspec() crafted tar member name → macro injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78367"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-78465",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-190",
      "title": "Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78465"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-78553",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-276",
      "title": "Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in RansomLook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78553"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-71920",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-476",
      "title": "DrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71920"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-71932",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DrayTek Corporation",
      "product": "VigorSwitch G2540xs",
      "cwe": "CWE-22",
      "title": "DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71932"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-78378",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ransomlook",
      "product": "ransomlook",
      "cwe": "CWE-200",
      "title": "Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78378"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2020-37268",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rocq-prover",
      "product": "rocq",
      "cwe": "CWE-778",
      "title": "Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37268"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-5006",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault",
      "cwe": "CWE-639",
      "title": "Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5006"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-17033",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-79",
      "title": "CVE-2026-17033 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17033"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-72703",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rocq-prover",
      "product": "rocq",
      "cwe": "CWE-670",
      "title": "Rocq Prover 8.20 before 9.2.0 Guard Checker Accepts Non-Terminating Fixpoint via Unchecked Cross-Calls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72703"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-72704",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rocq-prover",
      "product": "rocq",
      "cwe": "CWE-670",
      "title": "Rocq Prover through 9.2.0 Guard Checker Trusts Corrupted Recursive Tree After Transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72704"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-72705",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rocq-prover",
      "product": "rocq",
      "cwe": "CWE-670",
      "title": "Rocq Prover before 9.2.0 Guard Checker Accepts Fixpoint Passed as a Higher-Order Argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72705"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-72711",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leanprover",
      "product": "lean4",
      "cwe": "CWE-20",
      "title": "Lean 4 before 4.32.2 Kernel Accepts Opaque Declaration With an Unbound Free Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72711"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-72714",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rocq-prover",
      "product": "rocq",
      "cwe": "CWE-459",
      "title": "Rocq Prover through 9.2.0 Universe Checking State Desynchronised After Module Close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72714"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-76845",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cthackers",
      "product": "adm-zip",
      "cwe": "CWE-59",
      "title": "adm-zip 0.5.9 through 0.6.0 Arbitrary File Overwrite via Symlink Following on Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76845"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-63693",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Alienware Area 51m R2",
      "cwe": "CWE-379",
      "title": "Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63693"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-27364",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AnalogWP",
      "product": "Style Kits",
      "cwe": "CWE-862",
      "title": "WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27364"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-68516",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "openexr",
      "cwe": "CWE-121",
      "title": "OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68516"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-75509",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authlib",
      "product": "joserfc",
      "cwe": "CWE-290",
      "title": "joserfc claim-validation bypass via array-typed single-string claims (iss/sub/jti)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75509"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-78266",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "AutomatorWP",
      "cwe": "CWE-862",
      "title": "WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78266"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-78290",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "Magazine Blocks",
      "cwe": "CWE-79",
      "title": "WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78290"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-78323",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 10",
      "cwe": "CWE-295",
      "title": "Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78323"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-9728",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-367",
      "title": "TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9728"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-78269",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tammersoft",
      "product": "Shared Files",
      "cwe": "CWE-918",
      "title": "WordPress Shared Files plugin <= 1.7.69 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78269"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-34491",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "Metasys 14",
      "cwe": null,
      "title": "Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34491"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-78475",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-125",
      "title": "Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78475"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-17113",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-1287",
      "title": "Cri-o: cri-o: unvalidated image env var causes daemon crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17113"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-45404",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-go",
      "cwe": "CWE-362",
      "title": "OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45404"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-59295",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware (Broadcom)",
      "product": "io.micrometer:micrometer-core",
      "cwe": "CWE-401",
      "title": "Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59295"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-16781",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-674",
      "title": "SVG File Parsing Stack Exhaustion Vulnerability in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16781"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-78244",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Real Estate Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Real Estate Management System search.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78244"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-78245",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Pharmacy System",
      "cwe": "CWE-284",
      "title": "itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78245"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-78246",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Clinic Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Clinic Management System Admin Login login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78246"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-78247",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78247"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-78248",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78248"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-78434",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Faveo",
      "product": "Helpdesk",
      "cwe": "CWE-287",
      "title": "Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78434"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-78272",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "Fluent Support Pro",
      "cwe": "CWE-862",
      "title": "WordPress Fluent Support Pro plugin <= 2.3.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78272"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-78279",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "Fluent Support Pro",
      "cwe": "CWE-352",
      "title": "WordPress Fluent Support Pro plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78279"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2025-68833",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Hive",
      "cwe": "CWE-1240",
      "title": "HCL Hive is affected by use of a cryptographic primitive with a risky implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68833"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-13213",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13213"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-13343",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-200",
      "title": "Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13343"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-16782",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-125",
      "title": "SVG File Parsing Out-of-Bounds Read Vulnerability in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16782"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-21755",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Hive",
      "cwe": "CWE-307",
      "title": "HCL Hive is affected by a missing rate limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21755"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-67204",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BookStackApp",
      "product": "BookStack",
      "cwe": "CWE-863",
      "title": "BookStack < 26.05.4 Broken Access Control via Image Gallery API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67204"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-75099",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-200",
      "title": "Apache Allura: Unauthenticated REST disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75099"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-76837",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Baserow",
      "product": "Baserow",
      "cwe": "CWE-79",
      "title": "Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Display Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76837"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-77310",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "com.fasterxml.jackson.core:jackson-databind",
      "cwe": "CWE-918",
      "title": "jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77310"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-77923",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-863",
      "title": "Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77923"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-78258",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "Booking and Rental Manager",
      "cwe": "CWE-862",
      "title": "WordPress Booking and Rental Manager plugin <= 2.7.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78258"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-78278",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "Fluent Boards Pro",
      "cwe": "CWE-639",
      "title": "WordPress Fluent Boards Pro plugin <= 2.0.11 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78278"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-78291",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webful Creations",
      "product": "RepairBuddy",
      "cwe": "CWE-862",
      "title": "WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78291"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-65053",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horde",
      "product": "imp",
      "cwe": "CWE-79",
      "title": "Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65053"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-71503",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-79",
      "title": "Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71503"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-78277",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "FluentCRM Pro",
      "cwe": "CWE-918",
      "title": "WordPress FluentCRM Pro plugin <= 3.1.12 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78277"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-10618",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-79",
      "title": "Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribute Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10618"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-78337",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-434",
      "title": "Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78337"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-21759",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Hive",
      "cwe": "CWE-215",
      "title": "HCL Hive is affected by an information exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21759"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-55468",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wagtail",
      "product": "wagtail",
      "cwe": "CWE-280",
      "title": "Wagtail: Improper restriction handling on Pages admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55468"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-78280",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashThemes",
      "product": "Hash Form",
      "cwe": "CWE-352",
      "title": "WordPress Hash Form plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78280"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-76816",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-20",
      "title": "Netty: MQTT Topic Name and Client ID Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76816"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-75554",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hexpm",
      "product": "hexpm",
      "cwe": "CWE-613",
      "title": "Explicit organization scopes survive token refresh after membership ends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75554"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-78250",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytebot-ai",
      "product": "bytebot",
      "cwe": "CWE-404",
      "title": "bytebot-ai bytebot Agent Execution Workflow infinite loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78250"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-78435",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Faveo",
      "product": "Helpdesk",
      "cwe": "CWE-22",
      "title": "Faveo Helpdesk Logo SettingsController.php unlink path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78435"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-78430",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sworddut",
      "product": "mcp-ffmpeg-helper",
      "cwe": "CWE-77",
      "title": "sworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78430"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2022-30983",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-30983"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2025-26237",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-26237"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2025-26238",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-26238"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-30512",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating system. An authenticated low-privileged user can escape the kiosk environment by opening the application manual in the external PDF viewer and abusing the print functionality. Successful exploitation allows execution of arbitrary commands outside the kiosk environment with local administrator privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30512"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-52490",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52490"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-52492",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52492"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-56135",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a crafted directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56135"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-56136",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56136"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-59230",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59230"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-60093",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-23",
      "title": "Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60093"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-63621",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63621"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-66906",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-23",
      "title": "Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66906"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-66907",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-23",
      "title": "Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66907"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-66908",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-287",
      "title": "Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66908"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-71300",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71300"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-71832",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71832"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-75368",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75368"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-75369",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75369"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-75370",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75370"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-75371",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75371"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-75464",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75464"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-78329",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78329"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-78417",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Remote Desktop Manager",
      "cwe": "CWE-345",
      "title": "Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78417"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-21962",
      "detail": "ADDED TO KEV — CVE-2026-21962 (Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in). Remediation due August 27, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-21626",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-22373",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-22373 (Grassroot DICOM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-31823",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-31823. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-31828",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-31828. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-33775",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-33775. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-56005",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-56005. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-61258",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-61258. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62718",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62718 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10053",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10053 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12548",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12548 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-23745",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-23745 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-23950",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-23950 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24842 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25639 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26369",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26369 (JUNG eNet SMART HOME server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-30922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40175",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40175 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40938",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40938 (tektoncd pipeline). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41035",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42033 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42039 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42041 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42043",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42043 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42044 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42264 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44486 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44487 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44488 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44494 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45736",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59087",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59087 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59091",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59091 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66337",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66337 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66338 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66339",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66339 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66759",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66759 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6732",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6732 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78050",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78050 (Comfast CF-N1-S). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78051",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78051 (alexta69 MeTube). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78055",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78055 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78057",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78057 (sambitraj Student-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78059",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78059 (SourceCodester Stock Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78063 (Tenda CH22). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78112",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78112 (itsourcecode Hospital Management System Project in PHP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78140",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78140 (Dromara UJCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78142",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78142 (code-projects Barangay Resident Profiling Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78143",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78143 (code-projects Barangay Resident Profiling Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78145",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78145 (CTFd). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-72529",
      "detail": "DUE DATE PASSED — CVE-2026-72529 (TrueConf Server). CISA remediation deadline was August 23, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-50176",
      "detail": "RESCORED — CVE-2023-50176 (Fortinet FortiOS). CVSS 4 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-22373",
      "detail": "RESCORED — CVE-2024-22373 (Grassroot DICOM). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-36255",
      "detail": "RESCORED — CVE-2025-36255 (IBM DS8A00( R10.0 - R10.1 )). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-46252",
      "detail": "RESCORED — CVE-2025-46252 (Kofi Mokome Message Filter for Contact Form 7). CVSS 7.6 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16923",
      "detail": "RESCORED — CVE-2026-16923 (IBM AIX). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16925",
      "detail": "RESCORED — CVE-2026-16925 (IBM AIX). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16927",
      "detail": "RESCORED — CVE-2026-16927 (IBM AIX). CVSS 7.3 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16989",
      "detail": "RESCORED — CVE-2026-16989 (IBM AIX). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17015",
      "detail": "RESCORED — CVE-2026-17015 (IBM i). CVSS 5.4 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18102",
      "detail": "RESCORED — CVE-2026-18102 (IBM i). CVSS 3.5 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18652",
      "detail": "RESCORED — CVE-2026-18652 (Rapid7 Velociraptor). CVSS 4.9 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-22029",
      "detail": "RESCORED — CVE-2026-22029 (remix-run react-router). CVSS 8 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-23950",
      "detail": "RESCORED — CVE-2026-23950 (isaacs node-tar). CVSS 8.8 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-24049",
      "detail": "RESCORED — CVE-2026-24049 (pypa wheel). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33810",
      "detail": "RESCORED — CVE-2026-33810 (Go standard library crypto/x509). CVSS 7.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34100",
      "detail": "RESCORED — CVE-2026-34100 (guardian language-system). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34101",
      "detail": "RESCORED — CVE-2026-34101 (guardian language-system). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34102",
      "detail": "RESCORED — CVE-2026-34102 (guardian language-system). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34103",
      "detail": "RESCORED — CVE-2026-34103 (guardian language-system). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34104",
      "detail": "RESCORED — CVE-2026-34104 (guardian language-system). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34105",
      "detail": "RESCORED — CVE-2026-34105 (guardian language-system). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-39910",
      "detail": "RESCORED — CVE-2026-39910 (STACKIT IaaS API). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-41035",
      "detail": "RESCORED — CVE-2026-41035 (Samba rsync). CVSS 7.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42043",
      "detail": "RESCORED — CVE-2026-42043 (axios). CVSS 7.2 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42044",
      "detail": "RESCORED — CVE-2026-42044 (axios). CVSS 6.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42264",
      "detail": "RESCORED — CVE-2026-42264 (axios). CVSS 7.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-45736",
      "detail": "RESCORED — CVE-2026-45736 (websockets ws). CVSS 4.4 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4800",
      "detail": "RESCORED — CVE-2026-4800 (lodash). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66338",
      "detail": "RESCORED — CVE-2026-66338 (Red Hat Enterprise Linux 10). CVSS 5.4 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-6732",
      "detail": "RESCORED — CVE-2026-6732 (Red Hat Hardened Images). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-67340",
      "detail": "RESCORED — CVE-2026-67340 (ArcadeData arcadedb). CVSS 9.3 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70894",
      "detail": "RESCORED — CVE-2026-70894 (Oracle Corporation Oracle Hyperion Data Relationship Management). CVSS 7.7 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71474",
      "detail": "RESCORED — CVE-2026-71474 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 6.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7163",
      "detail": "RESCORED — CVE-2026-7163 (Red Hat multicluster engine for Kubernetes 2.1). CVSS 6.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71845",
      "detail": "RESCORED — CVE-2026-71845 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 6.3 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72822",
      "detail": "RESCORED — CVE-2026-72822 (getgrav grav). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72824",
      "detail": "RESCORED — CVE-2026-72824 (getgrav grav). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72826",
      "detail": "RESCORED — CVE-2026-72826 (getgrav grav). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72829",
      "detail": "RESCORED — CVE-2026-72829 (getgrav grav). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72830",
      "detail": "RESCORED — CVE-2026-72830 (getgrav grav). CVSS 9.3 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78156",
      "detail": "RESCORED — CVE-2026-78156 (Open5GS). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34692",
      "detail": "PATCH SHIPPED — CVE-2026-34692 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47935",
      "detail": "PATCH SHIPPED — CVE-2026-47935 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47936",
      "detail": "PATCH SHIPPED — CVE-2026-47936 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47939",
      "detail": "PATCH SHIPPED — CVE-2026-47939 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47941",
      "detail": "PATCH SHIPPED — CVE-2026-47941 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47942",
      "detail": "PATCH SHIPPED — CVE-2026-47942 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47943",
      "detail": "PATCH SHIPPED — CVE-2026-47943 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47944",
      "detail": "PATCH SHIPPED — CVE-2026-47944 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47945",
      "detail": "PATCH SHIPPED — CVE-2026-47945 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47946",
      "detail": "PATCH SHIPPED — CVE-2026-47946 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47947",
      "detail": "PATCH SHIPPED — CVE-2026-47947 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47948",
      "detail": "PATCH SHIPPED — CVE-2026-47948 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47949",
      "detail": "PATCH SHIPPED — CVE-2026-47949 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47950",
      "detail": "PATCH SHIPPED — CVE-2026-47950 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47951",
      "detail": "PATCH SHIPPED — CVE-2026-47951 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47953",
      "detail": "PATCH SHIPPED — CVE-2026-47953 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47954",
      "detail": "PATCH SHIPPED — CVE-2026-47954 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47956",
      "detail": "PATCH SHIPPED — CVE-2026-47956 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47957",
      "detail": "PATCH SHIPPED — CVE-2026-47957 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47958",
      "detail": "PATCH SHIPPED — CVE-2026-47958 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47962",
      "detail": "PATCH SHIPPED — CVE-2026-47962 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47966",
      "detail": "PATCH SHIPPED — CVE-2026-47966 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47970",
      "detail": "PATCH SHIPPED — CVE-2026-47970 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47972",
      "detail": "PATCH SHIPPED — CVE-2026-47972 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47973",
      "detail": "PATCH SHIPPED — CVE-2026-47973 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47974",
      "detail": "PATCH SHIPPED — CVE-2026-47974 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47975",
      "detail": "PATCH SHIPPED — CVE-2026-47975 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47977",
      "detail": "PATCH SHIPPED — CVE-2026-47977 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47978",
      "detail": "PATCH SHIPPED — CVE-2026-47978 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47980",
      "detail": "PATCH SHIPPED — CVE-2026-47980 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47981",
      "detail": "PATCH SHIPPED — CVE-2026-47981 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47982",
      "detail": "PATCH SHIPPED — CVE-2026-47982 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47983",
      "detail": "PATCH SHIPPED — CVE-2026-47983 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47985",
      "detail": "PATCH SHIPPED — CVE-2026-47985 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47986",
      "detail": "PATCH SHIPPED — CVE-2026-47986 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47987",
      "detail": "PATCH SHIPPED — CVE-2026-47987 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47989",
      "detail": "PATCH SHIPPED — CVE-2026-47989 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47990",
      "detail": "PATCH SHIPPED — CVE-2026-47990 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47991",
      "detail": "PATCH SHIPPED — CVE-2026-47991 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47993",
      "detail": "PATCH SHIPPED — CVE-2026-47993 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48250",
      "detail": "PATCH SHIPPED — CVE-2026-48250 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48251",
      "detail": "PATCH SHIPPED — CVE-2026-48251 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48256",
      "detail": "PATCH SHIPPED — CVE-2026-48256 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48258",
      "detail": "PATCH SHIPPED — CVE-2026-48258 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48264",
      "detail": "PATCH SHIPPED — CVE-2026-48264 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48265",
      "detail": "PATCH SHIPPED — CVE-2026-48265 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48266",
      "detail": "PATCH SHIPPED — CVE-2026-48266 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48268",
      "detail": "PATCH SHIPPED — CVE-2026-48268 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48271",
      "detail": "PATCH SHIPPED — CVE-2026-48271 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48276",
      "detail": "PATCH SHIPPED — CVE-2026-48276 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48277",
      "detail": "PATCH SHIPPED — CVE-2026-48277 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48280",
      "detail": "PATCH SHIPPED — CVE-2026-48280 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48281",
      "detail": "PATCH SHIPPED — CVE-2026-48281 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48282",
      "detail": "PATCH SHIPPED — CVE-2026-48282 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48283",
      "detail": "PATCH SHIPPED — CVE-2026-48283 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48285",
      "detail": "PATCH SHIPPED — CVE-2026-48285 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48286",
      "detail": "PATCH SHIPPED — CVE-2026-48286 (Adobe Campaign Classic). Fixed in Adobe Campaign Classic ACC v7: 7.4.3 build 9397."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48288",
      "detail": "PATCH SHIPPED — CVE-2026-48288 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48289",
      "detail": "PATCH SHIPPED — CVE-2026-48289 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48297",
      "detail": "PATCH SHIPPED — CVE-2026-48297 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48299",
      "detail": "PATCH SHIPPED — CVE-2026-48299 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48300",
      "detail": "PATCH SHIPPED — CVE-2026-48300 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48301",
      "detail": "PATCH SHIPPED — CVE-2026-48301 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48304",
      "detail": "PATCH SHIPPED — CVE-2026-48304 (Adobe Experience Manager as a Cloud Service). Fixed in Adobe Experience Manager as a Cloud Service 2026.5.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48307",
      "detail": "PATCH SHIPPED — CVE-2026-48307 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48313",
      "detail": "PATCH SHIPPED — CVE-2026-48313 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48314",
      "detail": "PATCH SHIPPED — CVE-2026-48314 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48315",
      "detail": "PATCH SHIPPED — CVE-2026-48315 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48316",
      "detail": "PATCH SHIPPED — CVE-2026-48316 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48363",
      "detail": "PATCH SHIPPED — CVE-2026-48363 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48364",
      "detail": "PATCH SHIPPED — CVE-2026-48364 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 10."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
