{
  "day": "2026-08-26",
  "boundary": "UTC calendar day",
  "published_count": 394,
  "by_severity": {
    "CRITICAL": 68,
    "HIGH": 149,
    "MEDIUM": 95,
    "LOW": 16
  },
  "kev_count": 1,
  "exploit_reference_count": 2,
  "awaiting_enrichment_count": 66,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-60004",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.824,
      "epss_percentile": 0.99637,
      "kev": true,
      "kev_due_at": "2026-08-28",
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-94",
      "title": "Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60004"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-70419",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02186,
      "epss_percentile": 0.81085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Cloud Disaster Recovery",
      "cwe": "CWE-78",
      "title": "Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70419"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-19042",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02004,
      "epss_percentile": 0.79331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Full Client",
      "cwe": "CWE-78",
      "title": "Command Injection in TeamViewer Desktop Client for Linux through Chat Link Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19042"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-55182",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01128,
      "epss_percentile": 0.6399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-77",
      "title": "LibreNMS: Remote Code Execution by Signal Alert Transportation Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55182"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-74770",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01065,
      "epss_percentile": 0.62244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect One",
      "cwe": "CWE-78",
      "title": "Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74770"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-77533",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01015,
      "epss_percentile": 0.60766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77533"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-71171",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01009,
      "epss_percentile": 0.60558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Cloud Disaster Recovery",
      "cwe": "CWE-78",
      "title": "Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71171"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-77554",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00992,
      "epss_percentile": 0.60033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Talk Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77554"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-68861",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00982,
      "epss_percentile": 0.59727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect One",
      "cwe": "CWE-78",
      "title": "Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68861"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-77537",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00943,
      "epss_percentile": 0.58493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77537"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-77552",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00893,
      "epss_percentile": 0.5689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Enterprise Audio/Video Bridge",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77552"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-77535",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00811,
      "epss_percentile": 0.5432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Network Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77535"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-77539",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00811,
      "epss_percentile": 0.54321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77539"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-77540",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00811,
      "epss_percentile": 0.54321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77540"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-77542",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00811,
      "epss_percentile": 0.5432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UID Enterprise Agent",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77542"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-77543",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00804,
      "epss_percentile": 0.54112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Access Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77543"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-77546",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00804,
      "epss_percentile": 0.54113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Access Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77546"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-77547",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00804,
      "epss_percentile": 0.54112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Access Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77547"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-77548",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00804,
      "epss_percentile": 0.54113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77548"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-19632",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00787,
      "epss_percentile": 0.53525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "TranslatePress – Translate Multilingual sites with AI Translation",
      "cwe": "CWE-640",
      "title": "TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19632"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-54569",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00776,
      "epss_percentile": 0.53177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "senaite",
      "product": "senaite.core",
      "cwe": "CWE-95",
      "title": "SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54569"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-15990",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00688,
      "epss_percentile": 0.50129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11",
      "product": "Formidable Charts",
      "cwe": "CWE-22",
      "title": "Formidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15990"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-80235",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00677,
      "epss_percentile": 0.49646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinking Software Technology",
      "product": "EFence",
      "cwe": "CWE-434",
      "title": "Thinking Software Technology｜EFence - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80235"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-18080",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00672,
      "epss_percentile": 0.49441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce",
      "cwe": "CWE-434",
      "title": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18080"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-18431",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00638,
      "epss_percentile": 0.47989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefusion",
      "product": "Avada (Fusion) Builder",
      "cwe": "CWE-862",
      "title": "Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18431"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-75977",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00623,
      "epss_percentile": 0.47313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kitae-park",
      "product": "Mang Board WP",
      "cwe": "CWE-269",
      "title": "Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75977"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-80233",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0062,
      "epss_percentile": 0.47146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CAYIN Technology",
      "product": "CAYIN CMS-WS",
      "cwe": "CWE-434",
      "title": "CAYIN Technology｜CAYIN CMS-WS/CMS-SE/SMP - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80233"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-58095",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00599,
      "epss_percentile": 0.46189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-122",
      "title": "ppp(8): incorrect length calculation in mp_Enddisc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58095"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-58096",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00599,
      "epss_percentile": 0.46189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-130",
      "title": "ppp(8): missing length validation in LcpDecodeConfig()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58096"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-80237",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00595,
      "epss_percentile": 0.45935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinking Software Technology",
      "product": "Efence",
      "cwe": "CWE-434",
      "title": "Thinking Software Technology｜Efence - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80237"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-9668",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00579,
      "epss_percentile": 0.45184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "SCP",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in ZTE SCP product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9668"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-59683",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00577,
      "epss_percentile": 0.45113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CalcProgrammer1",
      "product": "OpenRGB",
      "cwe": "CWE-73",
      "title": "OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59683"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2020-15874",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00561,
      "epss_percentile": 0.4428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-15874"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-74737",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00559,
      "epss_percentile": 0.44173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74737"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-65641",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00544,
      "epss_percentile": 0.43383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "One",
      "cwe": "CWE-288",
      "title": "A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65641"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-74746",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00543,
      "epss_percentile": 0.43345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: flowtable: publish GC-visible tuple last",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74746"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-73108",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00528,
      "epss_percentile": 0.42481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustdesk",
      "product": "rustdesk",
      "cwe": "CWE-770",
      "title": "RustDesk < 1.4.7 Uncontrolled Memory Allocation DoS via BytesCodec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73108"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-80528",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: avoid fs reclaim while using current->journal_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80528"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-80558",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: Avoid using invalid osd indices from primary_temp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80558"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-80561",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.4204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: fix multiple unsafe decodes in decode_locker()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80561"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-74743",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.41919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "macvlan: inherit needed_headroom and needed_tailroom from lowerdev",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74743"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-74744",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.41919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvlan: inherit needed_headroom and needed_tailroom from phy_dev",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74744"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-80428",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00517,
      "epss_percentile": 0.41814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ILIAS-eLearning e.V.",
      "product": "ILIAS",
      "cwe": "CWE-502",
      "title": "ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80428"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-80348",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00516,
      "epss_percentile": 0.41746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TarsCloud",
      "product": "TarsWeb",
      "cwe": "CWE-862",
      "title": "TarsWeb through 3.0.16 Missing Authorization on Patch Deploy, Download and Delete Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80348"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-59682",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00514,
      "epss_percentile": 0.41557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CalcProgrammer1",
      "product": "OpenRGB",
      "cwe": "CWE-73",
      "title": "Arbitrary file overwrite and deletion local and remote in OpenRGB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59682"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-80527",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: fix hanging __ceph_get_caps() with stale mds_wanted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80527"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-74851",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.40868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Pods",
      "cwe": "CWE-94",
      "title": "Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74851"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-18794",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CalcProgrammer1",
      "product": "OpenRGB",
      "cwe": "CWE-1288",
      "title": "OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18794"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-74742",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "veth: fix queue index used to wake the peer txq in veth_poll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74742"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-63041",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0046,
      "epss_percentile": 0.38041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-807",
      "title": "Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63041"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-65647",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.37916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk Migrator",
      "cwe": "CWE-59",
      "title": "Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65647"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-58474",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.37835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Andyyyy64",
      "product": "whichllm",
      "cwe": "CWE-94",
      "title": "whichllm < 0.5.16 Code Injection via run and snippet commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58474"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-80349",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00453,
      "epss_percentile": 0.37586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TarsCloud",
      "product": "TarsWeb",
      "cwe": "CWE-290",
      "title": "TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80349"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-12717",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00452,
      "epss_percentile": 0.37539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "BigQuery Data Transfer Service",
      "cwe": "CWE-74",
      "title": "Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12717"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-74741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74741"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-80519",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: finish crypto callback cleanup before peer release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80519"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-74752",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: validate cookie AUTH state before use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74752"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-80520",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.35898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: fix NULL dereference when killing missing key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80520"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-77550",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00428,
      "epss_percentile": 0.3556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-93",
      "title": "A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77550"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-65642",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00427,
      "epss_percentile": 0.35504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-639",
      "title": "Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65642"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2025-10903",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-835",
      "title": "Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10903"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-80214",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.34787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-78",
      "title": "LibreNMS Virtualisation Discovery Module RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80214"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-18884",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpgenie",
      "product": "WooCommerce Lottery",
      "cwe": "CWE-89",
      "title": "WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18884"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-14216",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-287",
      "title": "Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14216"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-80586",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.33415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: options: reset DSS fields in case of unexpected size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80586"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-54523",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.3308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyverno",
      "product": "kyverno",
      "cwe": "CWE-862",
      "title": "Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54523"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-19760",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emrevona",
      "product": "WP Fastest Cache – WordPress Cache Plugin",
      "cwe": "CWE-79",
      "title": "WP Fastest Cache <= 1.5.0 - Unauthenticated Stored Cross-Site Scripting via HTTP Host Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19760"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-80234",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CAYIN Technology",
      "product": "CAYIN CMS-WS",
      "cwe": "CWE-306",
      "title": "CAYIN Technology｜CAYIN CMS-WS/CMS-SE - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80234"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-81202",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Payroll System",
      "cwe": "CWE-287",
      "title": "itsourcecode Payroll System CRUD Operation ajax.php delete missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81202"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-46369",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-193",
      "title": "Nimiq: Validity store off by one error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46369"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-81030",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.31976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mage-ai",
      "product": "mage-ai",
      "cwe": "CWE-22",
      "title": "Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81030"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-80203",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.31603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-863",
      "title": "Grav before 1.0.18 Authentication Bypass via Scoped API Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80203"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-80346",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.3157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StarRocks",
      "product": "StarRocks",
      "cwe": "CWE-862",
      "title": "StarRocks through 4.0.13 Missing Authorization on DROP MATERIALIZED VIEW for Legacy Synchronous Materialized Views",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80346"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-75797",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Engine",
      "cwe": "CWE-22",
      "title": "AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75797"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-80557",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00379,
      "epss_percentile": 0.30803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: fix OOB read in decode_watchers() via missing bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80557"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-80205",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.30745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-1333",
      "title": "NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80205"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-54550",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.3054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "izpack",
      "product": "izpack",
      "cwe": "CWE-22",
      "title": "IzPack: Path Traversal in UnpackerBase allows writing files outside the installation directory via malicious pack entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54550"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-80589",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: stop the timeout timer when releasing a never added disk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80589"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-80236",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinking Software Technology",
      "product": "Efence",
      "cwe": "CWE-89",
      "title": "Thinking Software Technology｜Efence - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80236"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-18331",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strategy11team",
      "product": "Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More",
      "cwe": "CWE-79",
      "title": "Formidable Forms <= 6.33.1 - Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18331"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-80587",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.29171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: avoid combining some incoming suboptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80587"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-15203",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00361,
      "epss_percentile": 0.28889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Danfoss",
      "product": "iC7-Automation SP",
      "cwe": "CWE-1191",
      "title": "Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15203"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-74745",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.2866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eth: bnxt: avoid deadlock when canceling IRQ affinity notifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74745"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-74750",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.2866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: defer key slot crypto freeing to workqueue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74750"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-65956",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.28598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "KubePi",
      "cwe": "CWE-306",
      "title": "KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65956"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-54606",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JiHong88",
      "product": "suneditor",
      "cwe": "CWE-79",
      "title": "SunEditor: DOM XSS in SunEditor Embed Plugin via External Script Element After Iframe Embed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54606"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-19538",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-290",
      "title": "Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19538"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-63179",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.27821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wintercms",
      "product": "winter",
      "cwe": "CWE-22",
      "title": "Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63179"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-75960",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.27694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rently",
      "product": "Smart Home",
      "cwe": "CWE-522",
      "title": "Insufficiently Protected Credentials in Rently Smart Home",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75960"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-81028",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.27775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZLMediaKit",
      "product": "ZLMediaKit",
      "cwe": "CWE-22",
      "title": "ZLMediaKit downloadFile Root-Directory Confinement Bypass via Prefix Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81028"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-6178",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.27638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MuffinGroup",
      "product": "Betheme",
      "cwe": "CWE-79",
      "title": "Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6178"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-77801",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77801"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-77693",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Order Tip for WooCommerce",
      "cwe": "CWE-73",
      "title": "Order Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77693"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-80588",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: reclaim forward-allocated memory on RX path errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80588"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-18252",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-829",
      "title": "Inclusion of Functionality from Untrusted Control Sphere in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18252"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-16984",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates",
      "cwe": "CWE-284",
      "title": "WP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16984"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-74751",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv: lib: Fix ZBB strnlen reading past count boundary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74751"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-54245",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleetdm",
      "product": "fleet",
      "cwe": "CWE-89",
      "title": "Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54245"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-54553",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jowilf",
      "product": "starlette-admin",
      "cwe": "CWE-200",
      "title": "Starlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54553"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-19401",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.25712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-400",
      "title": "Remote UDP DoS by sending multiple DNS Cookie options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19401"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-18916",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.25712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-191",
      "title": "Remote TCP DoS by throttling the TCP receive window",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18916"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-77557",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.25542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect AI Key",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77557"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-79654",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-639",
      "title": "Ketello: katello content view history api cross-organization authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79654"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-15985",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.24917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "Classified Listing - Mobile Number Verification",
      "cwe": "CWE-289",
      "title": "Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15985"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-14550",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.24884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPCafe",
      "cwe": "CWE-862",
      "title": "WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14550"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-19226",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Royal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordion Widget Effect Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19226"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-80585",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00317,
      "epss_percentile": 0.23966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: fastopen: only mark MPTFO subflows with SYN data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80585"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-79921",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.2389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-770",
      "title": "amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79921"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-61792",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.2392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-22",
      "title": "Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61792"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-18664",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.23769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-284",
      "title": "Wrong interpretation of ACL ranges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18664"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-81031",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.23627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "idurar",
      "product": "idurar-erp-crm",
      "cwe": "CWE-639",
      "title": "IDURAR ERP CRM through 4.1.1 Account Takeover via Unverified Identifier on Password Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81031"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-13172",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-862",
      "title": "Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13172"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-13406",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal Addons for Elementor",
      "cwe": "CWE-862",
      "title": "Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13406"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-54614",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "debug_kit",
      "cwe": "CWE-470",
      "title": "DebugKit: MailPreview contains unsafe reflection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54614"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-81036",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.22944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stalwartlabs",
      "product": "stalwart",
      "cwe": "CWE-601",
      "title": "Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81036"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-66003",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.22931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-863",
      "title": "Frappe: Access control bypass via REST API dot-notation fields on linked doctypes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66003"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-54511",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.22777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dahlia",
      "product": "logtape",
      "cwe": "CWE-93",
      "title": "@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54511"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-74928",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.2277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Project Manager",
      "cwe": "CWE-862",
      "title": "WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74928"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-39275",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00305,
      "epss_percentile": 0.22635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39275"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-47841",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.22523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": null,
      "title": "WebAuthn User Verification Bypass via Session Serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47841"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-19271",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TÜBİTAK BİLGEM Software Technologies Research Institute",
      "product": "Liderahenk",
      "cwe": "CWE-90",
      "title": "Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19271"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-54556",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4s",
      "product": "http4s",
      "cwe": "CWE-409",
      "title": "Http4s: HTTP/2 Denial of Service with Ember Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54556"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-77549",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.003,
      "epss_percentile": 0.22152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-93",
      "title": "A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77549"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-81029",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-metadata",
      "product": "OpenMetadata",
      "cwe": "CWE-601",
      "title": "OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81029"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-73102",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustdesk",
      "product": "rustdesk",
      "cwe": "CWE-22",
      "title": "RustDesk Path Traversal via macOS Clipboard File-Paste",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73102"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-13404",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal Addons for Elementor",
      "cwe": "CWE-639",
      "title": "Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13404"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-16986",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking Package",
      "cwe": "CWE-284",
      "title": "Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16986"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-81032",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vesoft-inc",
      "product": "nebula",
      "cwe": "CWE-306",
      "title": "NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81032"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-77298",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-863",
      "title": "SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77298"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-19718",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BlogVault Backup & Staging",
      "cwe": "CWE-287",
      "title": "BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key Recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19718"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-81421",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.20835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ddfourtwo",
      "product": "sentry-selfhosted-mcp",
      "cwe": "CWE-918",
      "title": "ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81421"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-81027",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "songquanpeng",
      "product": "one-api",
      "cwe": "CWE-862",
      "title": "one-api through 0.6.10 Missing Authorization on URL-Parameter Channel Pinning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81027"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-65646",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.20531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-74",
      "title": "Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65646"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-80350",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.20568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OneUptime",
      "product": "OneUptime",
      "cwe": "CWE-918",
      "title": "OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80350"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-81033",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "automatisch",
      "product": "automatisch",
      "cwe": "CWE-204",
      "title": "Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81033"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-47837",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Config",
      "cwe": "CWE-306",
      "title": "Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47837"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-19094",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": "CWE-89",
      "title": "Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19094"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-68863",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.1987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect One",
      "cwe": "CWE-121",
      "title": "Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68863"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-81035",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.19867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "midday-ai",
      "product": "midday",
      "cwe": "CWE-862",
      "title": "Midday Missing Owner Check on Team Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81035"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-32639",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.19883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wintercms",
      "product": "winter",
      "cwe": "CWE-289",
      "title": "Winter: Broken access control in `Cms\\Controllers\\Index` allows cross-template actions and unauthorized asset uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32639"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-80347",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.19629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kazuph",
      "product": "mcp-fetch",
      "cwe": "CWE-918",
      "title": "mcp-fetch through 1.6.3 Server-Side Request Forgery via Unstripped IPv6 Literal Brackets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80347"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-14212",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.19488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-639",
      "title": "Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14212"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2020-15878",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00276,
      "epss_percentile": 0.1948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-15878"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2025-56798",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00276,
      "epss_percentile": 0.19561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-56798"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-63360",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63360"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-77532",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00271,
      "epss_percentile": 0.18841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "EdgeMAX EdgeSwitch",
      "cwe": "CWE-122",
      "title": "A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77532"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-77754",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.18878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-200",
      "title": "Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77754"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-77758",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.18878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Stripe Payment Forms by WP Full Pay",
      "cwe": "CWE-200",
      "title": "Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed Session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77758"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-46370",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.18757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleetdm",
      "product": "fleet",
      "cwe": "CWE-89",
      "title": "Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46370"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-47851",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.17726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": "CWE-674",
      "title": "Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47851"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-3002",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegstudio",
      "product": "Gutenverse – WordPress Blocks, Page Builder & Site Editor",
      "cwe": "CWE-79",
      "title": "Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3002"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-81203",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Online Food Ordering System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81203"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-15973",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15973"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-16444",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Full Client, Host, QuickSupport & Portable",
      "cwe": "CWE-73",
      "title": "Improper Validation of File Paths in TeamViewer Desktop Clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16444"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-77541",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Network Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77541"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-77757",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-22",
      "title": "Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77757"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-61790",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-284",
      "title": "Weblate: Team-enforced 2FA is bypassed for global permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61790"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-35445",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wintercms",
      "product": "winter",
      "cwe": "CWE-285",
      "title": "Winter: Authenticated backend users can bypass Users controller permission checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35445"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-47665",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-79",
      "title": "Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47665"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-48786",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleetdm",
      "product": "fleet",
      "cwe": "CWE-200",
      "title": "Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48786"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-47861",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-918",
      "title": "UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47861"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-80206",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-1333",
      "title": "NLTK 3.10.2 Regular Expression Denial of Service via tgrep",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80206"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-61617",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pterodactyl",
      "product": "wings",
      "cwe": "CWE-400",
      "title": "Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61617"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-62326",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-400",
      "title": "Weblate Has Uncontrolled Resource Consumption via",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62326"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-47862",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-22",
      "title": "ZipTransformer uses file_name header to build workDirectory path without sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47862"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-12587",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Resamania",
      "product": "Virtuagym",
      "cwe": "CWE-798",
      "title": "Embedded credentials in Virtuagym",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12587"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-16809",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16809"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-65930",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65930"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-3035",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-288",
      "title": "Authentication Bypass Using an Alternate Path or Channel in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3035"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-75798",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.14743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Engine",
      "cwe": "CWE-862",
      "title": "AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor Assistant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75798"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-77694",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.14743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-862",
      "title": "Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77694"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-69129",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.14624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "KubePi",
      "cwe": "CWE-639",
      "title": "KubePi: Insufficient per-cluster authorization checks in cluster management APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69129"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-47874",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Netty",
      "cwe": "CWE-770",
      "title": "Reactor Netty HTTP Server Denial of Service With Pipelined Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47874"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-3235",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "peterschulznl",
      "product": "WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards",
      "cwe": "CWE-639",
      "title": "WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5.68 - Unauthenticated Insecure Direct Object Reference to Data Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3235"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-77507",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-200",
      "title": "Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77507"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-47860",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AMQP",
      "cwe": null,
      "title": "Unbounded decompression of attacker-supplied compressed message bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47860"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-2388",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "designextreme",
      "product": "Reviews and Rating – Google Reviews",
      "cwe": "CWE-79",
      "title": "Reviews and Rating – Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2388"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-47856",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-502",
      "title": "JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47856"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-58108",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00233,
      "epss_percentile": 0.14003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "CodeChecker",
      "cwe": "CWE-284",
      "title": "Personal access token delete filters on Session columns while deleting from PersonalAccessTokenDB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58108"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-77534",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.1386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77534"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-77536",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.1386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77536"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-77553",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.1386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Access Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77553"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-75896",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.13885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TÜBİTAK BİLGEM Software Technologies Research Institute",
      "product": "Liderahenk",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75896"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-75062",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00231,
      "epss_percentile": 0.13703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "langfun",
      "cwe": "CWE-95",
      "title": "Eval Injection in google/langfun via default lf.query protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75062"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-80426",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.13799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "voxel51",
      "product": "fiftyone",
      "cwe": "CWE-79",
      "title": "FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80426"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-78146",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.13733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Newsletter Plugin",
      "cwe": "CWE-200",
      "title": "Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78146"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2020-15876",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00231,
      "epss_percentile": 0.13769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php, alertlog.inc.php, arp-search.inc.php, as-selection.inc.php, bills.inc.php, device_mibs.inc.php, device_oids.inc.php, edit-ports.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, mibs.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, tnmsneinfo.inc.php, and toner.inc.php (in includes/html/table).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-15876"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-75601",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.13653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "static-web-server",
      "product": "static-web-server",
      "cwe": "CWE-306",
      "title": "Static Web Server: Authentication bypass on /metrics endpoint when --basic-auth is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75601"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-7487",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.13635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-1280",
      "title": "Access Control Check Implemented After Asset is Accessed in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7487"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-55228",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-639",
      "title": "Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private project",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55228"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-19485",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00226,
      "epss_percentile": 0.13075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Vertex AI Search for Commerce",
      "cwe": "CWE-330",
      "title": "Bucket Squatting in Vertex AI Search for Commerce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19485"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-80183",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Keystone",
      "cwe": "CWE-843",
      "title": "In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal \"default\" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of \"None\" in list_role_assignments_for_tree.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80183"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-77538",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Connect Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77538"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-75411",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00224,
      "epss_percentile": 0.12875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75411"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-47857",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Core",
      "cwe": "CWE-190",
      "title": "Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-around",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47857"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-47863",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Core",
      "cwe": "CWE-835",
      "title": "Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47863"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-77611",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-863",
      "title": "SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a different object with the same basename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77611"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-77551",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0022,
      "epss_percentile": 0.1235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Connect Display Cast Pro",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77551"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-77317",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-863",
      "title": "SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77317"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-36851",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0022,
      "epss_percentile": 0.12352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36851"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-79938",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Power Protect Cyber Recovery",
      "cwe": "CWE-287",
      "title": "Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79938"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-46371",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleetdm",
      "product": "fleet",
      "cwe": "CWE-89",
      "title": "Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46371"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-49809",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Power Protect Cyber Recovery",
      "cwe": "CWE-89",
      "title": "Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49809"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-58097",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-122",
      "title": "ppp(8): missing length validation in mp_SetEnddisc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58097"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-15365",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00217,
      "epss_percentile": 0.11945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vivo",
      "product": "Kids Mode",
      "cwe": "CWE-841",
      "title": "A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15365"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-52103",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00217,
      "epss_percentile": 0.11932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52103"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-71054",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.11901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Java SE",
      "cwe": "CWE-770",
      "title": "Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71054"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-77695",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.11892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Return Refund and Exchange For WooCommerce",
      "cwe": "CWE-284",
      "title": "Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77695"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-32257",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.11784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wintercms",
      "product": "winter",
      "cwe": "CWE-79",
      "title": "Winter: Stored XSS through Brand Settings custom styles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32257"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-32258",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.11784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wintercms",
      "product": "winter",
      "cwe": "CWE-79",
      "title": "Winter: Stored XSS through Editor Settings custom styles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32258"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-77368",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.11759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-639",
      "title": "SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write to Tenant-Forbidden Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77368"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-77545",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00214,
      "epss_percentile": 0.11656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-489",
      "title": "A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77545"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-74930",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Project Manager",
      "cwe": "CWE-639",
      "title": "WP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74930"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-64632",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.10726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "ONE",
      "cwe": "CWE-522",
      "title": "A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64632"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-15387",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.10781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-349",
      "title": "Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15387"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-76148",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SASAKI Nobuyuki",
      "product": "CorvusSKK",
      "cwe": "CWE-94",
      "title": "CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76148"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-5092",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.1054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpsoul",
      "product": "Greenshift – animation and page builder blocks",
      "cwe": "CWE-79",
      "title": "Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5092"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-15366",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vivo",
      "product": "Kids Mode",
      "cwe": "CWE-653",
      "title": "A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15366"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-47852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": "CWE-377",
      "title": "Predictable cache directory location allows local ONNX model substitution in Spring AI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47852"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-19197",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-862",
      "title": "Broken access control in dashboard snapshots",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19197"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-47666",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.09917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-79",
      "title": "Penpot: Stored XSS via custom font family name injected into a @font-face style rule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47666"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-47834",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.09794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data JPA",
      "cwe": null,
      "title": "Spring Data JPA Sort expression validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47834"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-77789",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Stripe Payment Forms by WP Full Pay",
      "cwe": "CWE-639",
      "title": "Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77789"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-74771",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect One",
      "cwe": "CWE-639",
      "title": "Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74771"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-47859",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-770",
      "title": "Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47859"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-75363",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00194,
      "epss_percentile": 0.09126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75363"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-19220",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.08731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Forminator Forms",
      "cwe": "CWE-269",
      "title": "Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19220"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-77790",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0019,
      "epss_percentile": 0.0868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RegistrationMagic",
      "cwe": null,
      "title": "RegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77790"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-47844",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Netty",
      "cwe": null,
      "title": "Reactor Netty HTTP Server Leaks Exception Details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47844"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-71172",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Cloud Disaster Recovery",
      "cwe": "CWE-918",
      "title": "Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71172"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-41262",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleetdm",
      "product": "fleet",
      "cwe": "CWE-863",
      "title": "Fleet: Cross-Team Policy Data Exposure via Global Policy Read Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41262"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-55227",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-203",
      "title": "Observable object existence disclosure in private Weblate projects via globally scoped object lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55227"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-62249",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-200",
      "title": "Weblate: Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62249"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-43621",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SimpleMachines",
      "product": "SMF",
      "cwe": "CWE-863",
      "title": "Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43621"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-79940",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "iDRAC9",
      "cwe": "CWE-284",
      "title": "Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79940"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-74929",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Project Manager",
      "cwe": "CWE-284",
      "title": "WP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74929"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-75325",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.07547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75325"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-47850",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.0747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data REST",
      "cwe": "CWE-915",
      "title": "Spring Data REST allows mutation of the version property of immutable aggregates via PUT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47850"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2025-70293",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.07417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70293"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-47845",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Netty",
      "cwe": "CWE-290",
      "title": "Reactor Netty HTTP Server may incorrectly evaluate proxy addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47845"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-74740",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00175,
      "epss_percentile": 0.07078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74740"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-74734",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firewire: ohci: fix NULL pointer dereference in ar_context_release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74734"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-74738",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "regmap: sdw-mbq: don't call an unset readable_reg callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74738"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-75414",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75414"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-80529",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't swallow dquot recovery verification errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80529"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-80534",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix ilock leak on error in xfs_dq_get_next_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80534"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-32593",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.0666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wintercms",
      "product": "winter",
      "cwe": "CWE-89",
      "title": "Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32593"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-67275",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect One",
      "cwe": "CWE-1357",
      "title": "Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67275"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2025-70290",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0017,
      "epss_percentile": 0.0652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70290"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-75329",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00169,
      "epss_percentile": 0.06473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75329"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-75338",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00169,
      "epss_percentile": 0.06474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75338"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-52473",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00169,
      "epss_percentile": 0.06381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52473"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-75364",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00169,
      "epss_percentile": 0.06381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via sprintf() into the unquoted shell command `/etc/rrd/graphinterface %s %s` and executed by system() with root privileges. A remote authenticated attacker can inject arbitrary commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75364"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-75413",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00169,
      "epss_percentile": 0.06473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75413"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-48549",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios Enterprises, LLC.",
      "product": "Nagios Core",
      "cwe": "CWE-352",
      "title": "Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48549"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-80525",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80525"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-80532",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix another iunlink infinite loop bug in online fsck",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80532"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-80533",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80533"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-80535",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't double-lock when deleting a self-referential directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80535"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-80539",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: disallow multiple FENCE chunks in one submit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80539"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-80563",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80563"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-47843",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Netty",
      "cwe": null,
      "title": "Reactor Netty may incorrectly route traffic due to DNS resolver reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47843"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-80542",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80542"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-80562",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gpio: ml-ioh: use raw_spinlock_t for the register lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80562"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-80564",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gve: fix NULL dereference due to missing ptp adjfine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80564"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-80567",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.05894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80567"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-80573",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.05895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: iforce - validate input packet lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80573"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-56547",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00163,
      "epss_percentile": 0.05794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Traveler",
      "cwe": "CWE-20",
      "title": "An input reflection vulnerability affects HCL Traveler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56547"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-74735",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "l2tp: fix tunnel and session refcount leak on seq_file release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74735"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-74749",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rseq: Prevent hard lockup on granted time slice extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74749"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-13481",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13481"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-13480",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00161,
      "epss_percentile": 0.05572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-20",
      "title": "Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13480"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-81034",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gravitl",
      "product": "netmaker",
      "cwe": "CWE-295",
      "title": "Netmaker through 1.6.0 Improper Certificate Validation in SMTP Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81034"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-80566",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: hynitron_cstxxx - validate touch count and finger IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80566"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-80577",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/panthor: skip zero-sized firmware sections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80577"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2025-70340",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.0499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation of system messages and modification of trusted system-owned data, resulting in vertical privilege escalation and potential integrity violations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70340"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-26445",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read state. When enough such connections accumulate, the broker stops receiving any further epoll events for those sockets and eventually hangs in epoll_wait, effectively refusing to process new messages.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26445"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-26446",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26446"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-26447",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its internal subscription structures. This results in a heap use-after-free during StompClient destruction, causing the broker process to crash. An unauthenticated client can exploit this to reliably trigger a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26447"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-26448",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may dereference a pointer to a StompStreamSocket object that has already been freed. This results in a heap use-after-free and process crash. Because the protocol does not authenticate or restrict such sequences by default.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26448"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-26449",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26449"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-74754",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.0499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: core: pair EH runtime PM get and put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74754"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-75334",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without any parameterization or filtering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75334"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-80524",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "optee: ffa: Add NULL check in optee_ffa_lend_protmem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80524"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-80543",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.0499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Pad trailing CCA or EP11 message with zeros",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80543"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2025-51679",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.04911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-51679"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2025-61165",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.04912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61165"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-80571",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.04912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80571"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-80581",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00154,
      "epss_percentile": 0.04911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80581"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-80204",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00153,
      "epss_percentile": 0.04754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-863",
      "title": "Grav before 1.0.18 Authentication Bypass via Scoped API Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80204"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-80427",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nfriedly",
      "product": "bestzip",
      "cwe": "CWE-88",
      "title": "bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Option Delimiter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80427"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-47848",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Netty",
      "cwe": null,
      "title": "Reactor Netty WebSocket Client Leaks Credentials On Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47848"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-77508",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-302",
      "title": "Weblate: Unverified REST API email changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77508"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-68000",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00152,
      "epss_percentile": 0.04641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular expression blacklist filtering, yet keywords like CREATE/TABLE/SET/PREPARE/EXECUTE are not included in the list, allowing for bypassing. Attackers can execute stacked SQL statements without logging in.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68000"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-77652",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.0461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "Dia",
      "cwe": "CWE-122",
      "title": "Dia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palette index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77652"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-13479",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00151,
      "epss_percentile": 0.04598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13479"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-29988",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Milesight",
      "product": "AM102/102L V2",
      "cwe": "CWE-319",
      "title": "A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29988"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-54467",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TrustedFirmware",
      "product": "Trusted Firmware-M",
      "cwe": "CWE-283",
      "title": "On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54467"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2025-29419",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-29419"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-47842",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": null,
      "title": "Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext Correlation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47842"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-76784",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "HS103P3 / HS103P4 v5",
      "cwe": "CWE-325",
      "title": "Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76784"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-45694",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-79",
      "title": "LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45694"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-58092",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-288",
      "title": "Unauthorized credential switching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58092"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2023-42179",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-42179"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2025-61162",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61162"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2025-61163",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61163"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2025-61164",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61164"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-80551",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00144,
      "epss_percentile": 0.03974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Ensure first IDAW remains constant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80551"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-80554",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00144,
      "epss_percentile": 0.03973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Limit the number of channel program segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80554"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-77658",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.03975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "Dia",
      "cwe": "CWE-121",
      "title": "Dia: dia: stack buffer overflow in bus object via unvalidated handle count in project files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77658"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-75330",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00143,
      "epss_percentile": 0.03888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75330"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-75336",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00143,
      "epss_percentile": 0.03888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75336"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-54256",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.0394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wintercms",
      "product": "winter",
      "cwe": "CWE-284",
      "title": "Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54256"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-80536",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: bounds-check buffer log item's dirty bitmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80536"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-80544",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80544"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-77573",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-367",
      "title": "Weblate: DNS rebinding in VCS operations allows server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77573"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-80555",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Free all memory if cp_init() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80555"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-75332",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00139,
      "epss_percentile": 0.03596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75332"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-75340",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00139,
      "epss_percentile": 0.03592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75340"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-75333",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75333"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-48548",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios Enterprises, LLC.",
      "product": "Nagios Core",
      "cwe": "CWE-352",
      "title": "Nagios Core CSRF via cmd.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48548"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-74774",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect One",
      "cwe": "CWE-295",
      "title": "Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74774"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2025-51675",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of Service (DoS).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-51675"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2025-61478",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61478"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2025-61479",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61479"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2025-61480",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61480"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-75327",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75327"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-75328",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75328"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-75415",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing attackers to forge any user identity credential information, thereby causing sensitive information leakage.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75415"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-75466",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a SIGFPE and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75466"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-74736",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_bpf: reject dev-bound programs bound to a different device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74736"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-74739",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_u32: skip hash tables in u32_bind_class()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74739"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-74748",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: ipset: fix refcount race between list:set GC and swap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74748"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-79619",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenZFS",
      "product": "OpenZFS",
      "cwe": "CWE-863",
      "title": "OpenZFS: user-namespace capability check allows unprivileged local authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79619"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-80550",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Fix out of bounds check on CCW array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80550"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-75331",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75331"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-80545",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Improve EP11 CPRB length and overflow checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80545"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-80546",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Improve CCA CPRB length and overflow checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80546"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-80574",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.0318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80574"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-80584",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.0318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/qeth: validate user buffer length in SNMP and ARP query ioctls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80584"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-80549",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Move cp cleanup out of not operational",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80549"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-58090",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Use-after-free in unix SOCK_STREAM message handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58090"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-58091",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58091"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-78237",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admin By Request (ABR)",
      "product": "Admin By Request (ABR)",
      "cwe": "CWE-20",
      "title": "Insufficient input validation in Admin By Request (ABR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78237"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-80570",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: synaptics-rmi4 - zero report size on F54 work error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80570"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-76149",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SASAKI Nobuyuki",
      "product": "CorvusSKK",
      "cwe": "CWE-190",
      "title": "CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76149"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-80568",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: synaptics-rmi4 - block s_input when F54 queue is busy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80568"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-51106",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00133,
      "epss_percentile": 0.03126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51106"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-80552",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Ensure index for read/write regions are within range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80552"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-74747",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: revalidate ihl to prevent out-of-bounds access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74747"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-80540",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Fix UVD decode image min size calculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80540"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-80541",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: validate GEM_CREATE domain combinations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80541"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-80559",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: sur40 - fix input device registration ordering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80559"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-80560",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "openrisc: signal: do not restore privileged SR bits on sigreturn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80560"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-80547",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.0278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Implement a crw lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80547"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-80548",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Selectively expand io_mutex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80548"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-80553",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio_ccw: Cancel existing workqueues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80553"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-80522",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80522"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-80526",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: tas2562: Validate values for volume writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80526"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-80531",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.0278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: avoid UAF on sc->tempip in xrep_tempfile_create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80531"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-79902",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "Gimp: stack vla size underflow denial of service in seattle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79902"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-73335",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Digital Agency",
      "product": "Android App \"Myna Point\"",
      "cwe": "CWE-939",
      "title": "Android application \"Myna Point\" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73335"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-74753",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf: Reject exited events as group leaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74753"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-80537",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix off-by-one in rtrefcount btree root level validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80537"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-80530",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80530"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-80556",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80556"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-80523",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: spacemit: k3: set hdma clock as critical",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80523"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-80538",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: propagate errors from xfs_rtginode_load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80538"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-80576",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: reject oversized IBs with per-ring packet limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80576"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-80521",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "af_unix: Unlink scc_entry in unix_del_edge().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80521"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-80565",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qce - fix error path in devm_qce_register_algs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80565"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-80569",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80569"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-80575",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: cs40l50-vibra - validate custom data from user space",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80575"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-58089",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.01984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-273",
      "title": "hwpmc fails to detach PMCs during exec credential transitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58089"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-80572",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: byd - synchronize timer deletion before freeing private data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80572"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-9805",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Insyde Software",
      "product": "InsydeH2O",
      "cwe": "CWE-787",
      "title": "FMTSWriteUseIntelLib: FMTS SMM IHISI Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9805"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-80578",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: core: Fix pointer desynchronization in fb_io_read()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80578"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-58070",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-532",
      "title": "A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58070"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2025-62341",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00116,
      "epss_percentile": 0.01791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Connections",
      "cwe": "CWE-918",
      "title": "HCL Connections is vulnerable to server-side request forgery (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62341"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-80579",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: clear fb_info->mode before deleting a videomode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80579"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-80580",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: bound mode sysfs output to the sysfs buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80580"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-80582",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/shmem_helper: Check VMA boundaries for PMD mappings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80582"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-80583",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80583"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-79939",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Power Protect Cyber Recovery",
      "cwe": "CWE-61",
      "title": "Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79939"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-58094",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-367",
      "title": "TOCTOU race in POSIX shared memory large page configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58094"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-80158",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ceph Storage 5",
      "cwe": "CWE-214",
      "title": "Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80158"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-21808",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.00984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "BigFix Quantum Risk Analyzer",
      "cwe": "CWE-532",
      "title": "HCL BigFix Quantum Risk Analyzer is affected by logging sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21808"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-78236",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admin By Request (ABR)",
      "product": "Admin By Request (ABR)",
      "cwe": "CWE-284",
      "title": "Insecure PIN derivation mechanism in Admin By Request (ABR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78236"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-21807",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00092,
      "epss_percentile": 0.00572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "BigFix Quantum Risk Analyzer",
      "cwe": "CWE-121",
      "title": "HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21807"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-21809",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "BigFix Quantum Risk Analyzer",
      "cwe": "CWE-209",
      "title": "HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21809"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-54548",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siemens",
      "product": "kas",
      "cwe": "CWE-295",
      "title": "kas: Persistent SSH Host Key Checking Disablement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54548"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-58093",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0009,
      "epss_percentile": 0.00505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-362",
      "title": "Kernel use-after-free via tty ioctls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58093"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-47836",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Config",
      "cwe": null,
      "title": "Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47836"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-21810",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00074,
      "epss_percentile": 0.00081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "BigFix Quantum Risk Analyzer",
      "cwe": "CWE-494",
      "title": "HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21810"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2015-3246",
      "detail": "ADDED TO KEV — CVE-2015-3246. Remediation due September 9, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2015-5287",
      "detail": "ADDED TO KEV — CVE-2015-5287. Remediation due September 9, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2019-1068",
      "detail": "ADDED TO KEV — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). Remediation due August 29, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2021-23758",
      "detail": "ADDED TO KEV — CVE-2021-23758 (AjaxPro.2). Remediation due September 9, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2022-0995",
      "detail": "ADDED TO KEV — CVE-2022-0995 (kernel). Remediation due September 9, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-60004",
      "detail": "ADDED TO KEV — CVE-2026-60004 (Gitea). Remediation due August 28, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-8452",
      "detail": "ADDED TO KEV — CVE-2026-8452 (NetScaler ADC). Remediation due August 29, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-47983",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-47983 (mra13 Accept Stripe Payments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-14041",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-14041 (Legion of the Bouncy Castle Inc. BC-JAVA). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59693",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59693. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59694",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59694. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59695",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59695. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59696",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59696. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59697",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59697. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59698",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59698. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59699",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59699. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59700",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59700. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59701",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59701. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59702",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59702. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59703",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59703. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59704",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59704. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-59705",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-59705. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-21901",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-21901 (Juniper Networks Junos OS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-22306",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-22306 (Ozols Grupa OZOLS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25639 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40175",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40175 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41242",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42033 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42039 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42041 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42043",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42043 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42044 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44486 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44487 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44488 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44494 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45137",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45137 (solana-foundation anchor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45736",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50151",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50151 (oras-project oras-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54344",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54344 (ToolJet). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54673",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54673 (electron-userland electron-builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58192",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58192 (appium). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58500",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58500 (appium-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59151",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59151 (prowler-cloud prowler). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59723",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59723 (cline). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59887",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59887 (markdown-it linkify-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-60004",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-60004 (Gitea). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65053",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65053 (horde imp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6732",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6732 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71504",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71504 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71506",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71506 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71509",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71509 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71511",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71511 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72703",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72703 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72705",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72705 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74932",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74932 (Unknown WP Fastest Cache). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76071",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76071 (Netis Systems NC63). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77681",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77681 (CodeAstro Online Job Portal). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77946",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77946 (TRENDnet TEW-821DAP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78049 (Systerel S2OPC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78054",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78054 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78056",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78056 (sambitraj Student-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78060",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78060 (SourceCodester Stock Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78115",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78115 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78122",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78122 (Tecnativa docker-socket-proxy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78141",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78141 (Tenda CH22). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78144",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78144 (code-projects Barangay Resident Profiling Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78166",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78166 (provectus kafka-ui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78168",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78168 (EFM ipTIME T24000M). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78171",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78171 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78181 (ractivejs ractive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78185",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78185 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78198",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78198 (SourceCodester Simple Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78201",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78201 (itsourcecode Payroll System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78244",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78244 (itsourcecode Real Estate Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78247",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78247 (SourceCodester Simple Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78250",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78250 (bytebot-ai bytebot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78435",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78435 (Faveo Helpdesk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78638",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78638 (peerigon unzip-crx). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79623",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79623 (FishCodeTech Muteki). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79792",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79792 (zackees transcribe-anything). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79793",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79793 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79845",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79845 (code-projects Simple Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79911",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79911 (TOTOLINK N600R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79912",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79912 (TOTOLINK N600R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80182",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80182 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80184",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80184 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-68820",
      "detail": "DUE DATE PASSED — CVE-2026-68820 (Microsoft Windows 10 Version 1607). CISA remediation deadline was August 25, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-59700",
      "detail": "RESCORED — CVE-2025-59700. CVSS 5.8 → 3.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-59704",
      "detail": "RESCORED — CVE-2025-59704. CVSS 7.8 → 4.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16708",
      "detail": "RESCORED — CVE-2026-16708 (IBM Db2 Mirror for i). CVSS 8.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19582",
      "detail": "RESCORED — CVE-2026-19582 (Red Hat Migration Toolkit for Containers). CVSS 7.8 → 0 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4932",
      "detail": "RESCORED — CVE-2026-4932 (IBM PowerVM Hypervisor). CVSS 4.2 → 4.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54344",
      "detail": "RESCORED — CVE-2026-54344 (ToolJet). CVSS 4.7 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58192",
      "detail": "RESCORED — CVE-2026-58192 (appium). CVSS 8.6 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-5917",
      "detail": "RESCORED — CVE-2026-5917 (libgit2). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62613",
      "detail": "RESCORED — CVE-2026-62613 (Oracle Corporation Oracle Reports Developer). CVSS 9.3 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62623",
      "detail": "RESCORED — CVE-2026-62623 (Oracle Corporation Oracle Reports Developer). CVSS 8.8 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62631",
      "detail": "RESCORED — CVE-2026-62631 (Oracle Corporation Oracle Reports Developer). CVSS 8.8 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62637",
      "detail": "RESCORED — CVE-2026-62637 (Oracle Corporation Oracle Reports Developer). CVSS 9.3 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70670",
      "detail": "RESCORED — CVE-2026-70670 (Oracle Corporation Oracle Reports Developer). CVSS 9.6 → 7.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70674",
      "detail": "RESCORED — CVE-2026-70674 (Oracle Corporation Oracle Reports Developer). CVSS 8.8 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70715",
      "detail": "RESCORED — CVE-2026-70715 (Oracle Corporation Oracle Autonomous Health Framework). CVSS 8.8 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70717",
      "detail": "RESCORED — CVE-2026-70717 (Oracle Corporation Oracle Autonomous Health Framework). CVSS 7.7 → 6.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7868",
      "detail": "RESCORED — CVE-2026-7868 (IBM OPENBMC). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-8058",
      "detail": "RESCORED — CVE-2026-8058 (IBM OPENBMC). CVSS 4.5 → 4.9 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-74234",
      "detail": "REJECTED — CVE-2026-74234 (Legora). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78466",
      "detail": "REJECTED — CVE-2026-78466 (Fluent Boars Fluent Boards Pro). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78467",
      "detail": "REJECTED — CVE-2026-78467 (Fluent Support Pro). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78468",
      "detail": "REJECTED — CVE-2026-78468 (FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-10090",
      "detail": "PATCH SHIPPED — CVE-2026-10090 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15218",
      "detail": "PATCH SHIPPED — CVE-2026-15218 (Red Hat OpenShift AI 3.4). Fixed in Red Hat OpenShift AI 3.4 1787153683."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15378",
      "detail": "PATCH SHIPPED — CVE-2026-15378 (Red Hat OpenShift AI 3.4). Fixed in Red Hat OpenShift AI 3.4 1787360218."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18874",
      "detail": "PATCH SHIPPED — CVE-2026-18874 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787683560."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34657",
      "detail": "PATCH SHIPPED — CVE-2026-34657 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34691",
      "detail": "PATCH SHIPPED — CVE-2026-34691 (Adobe Experience Manager 6.5 LTS). Fixed in Adobe Experience Manager 6.5 LTS SP2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34693",
      "detail": "PATCH SHIPPED — CVE-2026-34693 (Adobe Experience Manager 6.5 LTS). Fixed in Adobe Experience Manager 6.5 LTS SP2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34694",
      "detail": "PATCH SHIPPED — CVE-2026-34694 (Adobe Experience Manager 6.5 LTS). Fixed in Adobe Experience Manager 6.5 LTS SP2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34695",
      "detail": "PATCH SHIPPED — CVE-2026-34695 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34696",
      "detail": "PATCH SHIPPED — CVE-2026-34696 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34697",
      "detail": "PATCH SHIPPED — CVE-2026-34697 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34698",
      "detail": "PATCH SHIPPED — CVE-2026-34698 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34699",
      "detail": "PATCH SHIPPED — CVE-2026-34699 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34700",
      "detail": "PATCH SHIPPED — CVE-2026-34700 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34701",
      "detail": "PATCH SHIPPED — CVE-2026-34701 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34702",
      "detail": "PATCH SHIPPED — CVE-2026-34702 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34703",
      "detail": "PATCH SHIPPED — CVE-2026-34703 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34704",
      "detail": "PATCH SHIPPED — CVE-2026-34704 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34705",
      "detail": "PATCH SHIPPED — CVE-2026-34705 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34706",
      "detail": "PATCH SHIPPED — CVE-2026-34706 (Adobe InCopy). Fixed in InCopy 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34707",
      "detail": "PATCH SHIPPED — CVE-2026-34707 (Adobe InCopy). Fixed in InCopy 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34708",
      "detail": "PATCH SHIPPED — CVE-2026-34708 (Adobe InCopy). Fixed in InCopy 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34709",
      "detail": "PATCH SHIPPED — CVE-2026-34709 (Adobe Substance 3D Sampler). Fixed in Adobe Substance 3D Sampler 6.0.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34710",
      "detail": "PATCH SHIPPED — CVE-2026-34710 (Adobe Substance 3D Sampler). Fixed in Adobe Substance 3D Sampler 6.0.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34711",
      "detail": "PATCH SHIPPED — CVE-2026-34711 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34712",
      "detail": "PATCH SHIPPED — CVE-2026-34712 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34713",
      "detail": "PATCH SHIPPED — CVE-2026-34713 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47902",
      "detail": "PATCH SHIPPED — CVE-2026-47902 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47903",
      "detail": "PATCH SHIPPED — CVE-2026-47903 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47904",
      "detail": "PATCH SHIPPED — CVE-2026-47904 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47905",
      "detail": "PATCH SHIPPED — CVE-2026-47905 (Adobe Content Credentials Rust SDK). Fixed in Content Credentials Rust SDK c2pa-v0.85.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47906",
      "detail": "PATCH SHIPPED — CVE-2026-47906 (Adobe Dreamweaver Desktop). Fixed in Dreamweaver Desktop 21.8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47907",
      "detail": "PATCH SHIPPED — CVE-2026-47907 (Adobe Dreamweaver Desktop). Fixed in Dreamweaver Desktop 21.8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47908",
      "detail": "PATCH SHIPPED — CVE-2026-47908 (Adobe Dreamweaver Desktop). Fixed in Dreamweaver Desktop 21.8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47909",
      "detail": "PATCH SHIPPED — CVE-2026-47909 (Adobe Dreamweaver Desktop). Fixed in Dreamweaver Desktop 21.8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47910",
      "detail": "PATCH SHIPPED — CVE-2026-47910 (Adobe Dreamweaver Desktop). Fixed in Dreamweaver Desktop 21.8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47911",
      "detail": "PATCH SHIPPED — CVE-2026-47911 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47912",
      "detail": "PATCH SHIPPED — CVE-2026-47912 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47913",
      "detail": "PATCH SHIPPED — CVE-2026-47913 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47914",
      "detail": "PATCH SHIPPED — CVE-2026-47914 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47915",
      "detail": "PATCH SHIPPED — CVE-2026-47915 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47916",
      "detail": "PATCH SHIPPED — CVE-2026-47916 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47917",
      "detail": "PATCH SHIPPED — CVE-2026-47917 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47918",
      "detail": "PATCH SHIPPED — CVE-2026-47918 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47919",
      "detail": "PATCH SHIPPED — CVE-2026-47919 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47920",
      "detail": "PATCH SHIPPED — CVE-2026-47920 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47921",
      "detail": "PATCH SHIPPED — CVE-2026-47921 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47923",
      "detail": "PATCH SHIPPED — CVE-2026-47923 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47924",
      "detail": "PATCH SHIPPED — CVE-2026-47924 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47925",
      "detail": "PATCH SHIPPED — CVE-2026-47925 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47926",
      "detail": "PATCH SHIPPED — CVE-2026-47926 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47927",
      "detail": "PATCH SHIPPED — CVE-2026-47927 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47928",
      "detail": "PATCH SHIPPED — CVE-2026-47928 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47929",
      "detail": "PATCH SHIPPED — CVE-2026-47929 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47930",
      "detail": "PATCH SHIPPED — CVE-2026-47930 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47931",
      "detail": "PATCH SHIPPED — CVE-2026-47931 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47932",
      "detail": "PATCH SHIPPED — CVE-2026-47932 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47933",
      "detail": "PATCH SHIPPED — CVE-2026-47933 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47934",
      "detail": "PATCH SHIPPED — CVE-2026-47934 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47937",
      "detail": "PATCH SHIPPED — CVE-2026-47937 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47938",
      "detail": "PATCH SHIPPED — CVE-2026-47938 (Adobe Campaign Classic). Fixed in Adobe Campaign Classic ACC v7: 7.4.3 build 9396."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47952",
      "detail": "PATCH SHIPPED — CVE-2026-47952 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47955",
      "detail": "PATCH SHIPPED — CVE-2026-47955 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47959",
      "detail": "PATCH SHIPPED — CVE-2026-47959 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47960",
      "detail": "PATCH SHIPPED — CVE-2026-47960 (Adobe ColdFusion 2025). Fixed in ColdFusion 2025 9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47961",
      "detail": "PATCH SHIPPED — CVE-2026-47961 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47963",
      "detail": "PATCH SHIPPED — CVE-2026-47963 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47964",
      "detail": "PATCH SHIPPED — CVE-2026-47964 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-47965",
      "detail": "PATCH SHIPPED — CVE-2026-47965 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48267",
      "detail": "PATCH SHIPPED — CVE-2026-48267 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48291",
      "detail": "PATCH SHIPPED — CVE-2026-48291 (Adobe Format Plugins). Fixed in Format Plugins 1.1.3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48292",
      "detail": "PATCH SHIPPED — CVE-2026-48292 (Adobe Format Plugins). Fixed in Format Plugins 1.1.3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48293",
      "detail": "PATCH SHIPPED — CVE-2026-48293 (Adobe InDesign Desktop). Fixed in InDesign Desktop 21.4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48303",
      "detail": "PATCH SHIPPED — CVE-2026-48303 (Adobe Campaign Classic). Fixed in Adobe Campaign Classic ACC v7: 7.4.3 build 9396."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48305",
      "detail": "PATCH SHIPPED — CVE-2026-48305 (Adobe Substance 3D Sampler). Fixed in Adobe Substance 3D Sampler 6.0.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48306",
      "detail": "PATCH SHIPPED — CVE-2026-48306 (Adobe Substance 3D Sampler). Fixed in Adobe Substance 3D Sampler 6.0.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48373",
      "detail": "PATCH SHIPPED — CVE-2026-48373 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21662."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-48389",
      "detail": "PATCH SHIPPED — CVE-2026-48389 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-4897",
      "detail": "PATCH SHIPPED — CVE-2026-4897 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:125-4.el10_2.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-64927",
      "detail": "PATCH SHIPPED — CVE-2026-64927 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787260663."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66780",
      "detail": "PATCH SHIPPED — CVE-2026-66780 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787689013."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66781",
      "detail": "PATCH SHIPPED — CVE-2026-66781 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787689013."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66792",
      "detail": "PATCH SHIPPED — CVE-2026-66792 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787262214."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66793",
      "detail": "PATCH SHIPPED — CVE-2026-66793 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787683327."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66878",
      "detail": "PATCH SHIPPED — CVE-2026-66878 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-67567",
      "detail": "PATCH SHIPPED — CVE-2026-67567 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-70398",
      "detail": "PATCH SHIPPED — CVE-2026-70398 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787260689."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-70495",
      "detail": "PATCH SHIPPED — CVE-2026-70495 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688827."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-70496",
      "detail": "PATCH SHIPPED — CVE-2026-70496 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688827."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71467",
      "detail": "PATCH SHIPPED — CVE-2026-71467 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1787229541."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71468",
      "detail": "PATCH SHIPPED — CVE-2026-71468 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787689524."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71469",
      "detail": "PATCH SHIPPED — CVE-2026-71469 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787689524."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71470",
      "detail": "PATCH SHIPPED — CVE-2026-71470 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688827."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71471",
      "detail": "PATCH SHIPPED — CVE-2026-71471 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688827."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71472",
      "detail": "PATCH SHIPPED — CVE-2026-71472 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688827."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71473",
      "detail": "PATCH SHIPPED — CVE-2026-71473 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688827."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71474",
      "detail": "PATCH SHIPPED — CVE-2026-71474 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688993."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71475",
      "detail": "PATCH SHIPPED — CVE-2026-71475 (Red Hat Advanced Cluster Management for Kubernetes 2.13). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.13 1787259125."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71845",
      "detail": "PATCH SHIPPED — CVE-2026-71845 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688993."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71846",
      "detail": "PATCH SHIPPED — CVE-2026-71846 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688993."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-72508",
      "detail": "PATCH SHIPPED — CVE-2026-72508 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-72526",
      "detail": "PATCH SHIPPED — CVE-2026-72526 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787260689."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-73122",
      "detail": "PATCH SHIPPED — CVE-2026-73122 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787260663."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-73137",
      "detail": "PATCH SHIPPED — CVE-2026-73137 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-73834",
      "detail": "PATCH SHIPPED — CVE-2026-73834 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263322."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-75485",
      "detail": "PATCH SHIPPED — CVE-2026-75485 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263322."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-76139",
      "detail": "PATCH SHIPPED — CVE-2026-76139 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787704547."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-76827",
      "detail": "PATCH SHIPPED — CVE-2026-76827 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688957."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
