{
  "day": "2026-08-27",
  "boundary": "UTC calendar day",
  "published_count": 437,
  "by_severity": {
    "CRITICAL": 65,
    "HIGH": 153,
    "MEDIUM": 131,
    "LOW": 22
  },
  "kev_count": 0,
  "exploit_reference_count": 6,
  "awaiting_enrichment_count": 66,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-47864",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.03441,
      "epss_percentile": 0.88134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-502",
      "title": "Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47864"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-74233",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02633,
      "epss_percentile": 0.84388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zbtlink",
      "product": "WE1326",
      "cwe": "CWE-78",
      "title": "Zbtlink MQWrt infosrvd Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74233"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-76060",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.02315,
      "epss_percentile": 0.82031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoneminder",
      "product": "Zoneminder",
      "cwe": "CWE-78",
      "title": "OS Command Injection in PayRange API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76060"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-78037",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0122,
      "epss_percentile": 0.66052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xiiaozet",
      "product": "Xiiaozet LK100W",
      "cwe": "CWE-78",
      "title": "Xiiaozet LK100W OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78037"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-57499",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00958,
      "epss_percentile": 0.58432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "limanmys",
      "product": "core",
      "cwe": "CWE-20",
      "title": "Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57499"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-54718",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00724,
      "epss_percentile": 0.5105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silverstripe",
      "product": "silverstripe-advancedworkflow",
      "cwe": "CWE-1336",
      "title": "Silverstripe Advanced Workflow: Remote code execution via advanced workflow email template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54718"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-76639",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00714,
      "epss_percentile": 0.50697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unitree Robotics",
      "product": "G1 EDU",
      "cwe": "CWE-22",
      "title": "Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76639"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-78612",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00697,
      "epss_percentile": 0.50091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-502",
      "title": "Dimension SQL Injection in Scheduled Report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78612"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-78614",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00697,
      "epss_percentile": 0.50091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-502",
      "title": "Dimension SQL Injection in Audit Report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78614"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-76943",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00674,
      "epss_percentile": 0.49216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xiiaozet",
      "product": "Xiiaozet LK100W",
      "cwe": "CWE-288",
      "title": "Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76943"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-81562",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00634,
      "epss_percentile": 0.47579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AlexGladkov",
      "product": "claude-in-mobile",
      "cwe": "CWE-77",
      "title": "AlexGladkov claude-in-mobile client.ts execSync os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81562"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-40526",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00623,
      "epss_percentile": 0.47088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Volmarg",
      "product": "personal-management-system",
      "cwe": "CWE-22",
      "title": "Volmarg Personal Management System Path Traversal via get-file Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40526"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-78613",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00607,
      "epss_percentile": 0.46309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-89",
      "title": "Dimension SQL Injection in Log Viewer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78613"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-78002",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00606,
      "epss_percentile": 0.46258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-131",
      "title": "Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78002"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-37003",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00603,
      "epss_percentile": 0.46136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execution sinks including exec(), runpy.run_path(), and subprocess.run(). An unauthenticated attacker can exploit this by embedding malicious instructions in content processed by the agent (such as web pages or documents), allowing for arbitrary code and OS command execution on the host server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37003"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-61800",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0059,
      "epss_percentile": 0.45541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-22",
      "title": "Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61800"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-81934",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00585,
      "epss_percentile": 0.45302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redis",
      "product": "Redis",
      "cwe": "CWE-416",
      "title": "Redis TLS pending-data list use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81934"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-81096",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00574,
      "epss_percentile": 0.44764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mims-harvard",
      "product": "ToolUniverse",
      "cwe": "CWE-94",
      "title": "ToolUniverse through 1.2.6 Unauthenticated Remote Code Execution via python_code_executor Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81096"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-78239",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00552,
      "epss_percentile": 0.43699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xiiaozet",
      "product": "Xiiaozet LK100W",
      "cwe": "CWE-306",
      "title": "Xiiaozet LK100W Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78239"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-35868",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00539,
      "epss_percentile": 0.4297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35868"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-81735",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00534,
      "epss_percentile": 0.42725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytedance",
      "product": "UI-TARS-desktop",
      "cwe": "CWE-306",
      "title": "UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81735"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-73125",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0053,
      "epss_percentile": 0.4248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-306",
      "title": "Ebyte NE2-D11 Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73125"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-81625",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0053,
      "epss_percentile": 0.42482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Greenbone",
      "product": "Greenbone OS",
      "cwe": "CWE-787",
      "title": "Stack buffer overflow in Greenbone OS and openvas-scanner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81625"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-35869",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00528,
      "epss_percentile": 0.42379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35869"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-78286",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "INFINITUM FORM",
      "product": "Geo Controller",
      "cwe": "CWE-502",
      "title": "WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78286"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-78292",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hashthemes",
      "product": "Hash Form",
      "cwe": "CWE-502",
      "title": "WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78292"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-71187",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.4195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-603",
      "title": "Ebyte NE2-D11 Use of Client-Side Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71187"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-81098",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00505,
      "epss_percentile": 0.40891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-telnyx",
      "product": "telnyx-mcp",
      "cwe": "CWE-306",
      "title": "Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81098"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-78276",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.40771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "Fluent Boards Pro",
      "cwe": "CWE-502",
      "title": "WordPress Fluent Boards Pro plugin <= 2.0.11 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78276"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-75020",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.40788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-90",
      "title": "Apache APISIX: ldap-auth plugin cross-subtree identity impersonation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75020"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-78275",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00503,
      "epss_percentile": 0.40787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "Fluent Boards Pro",
      "cwe": "CWE-22",
      "title": "WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78275"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-80212",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.39872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruby",
      "product": "resolv",
      "cwe": "CWE-770",
      "title": "An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource record (type, class) pair, or each unknown SvcParamKey, encountered while decoding a response. Each generated class was permanently registered both as a constant on Resource (or SvcParam::Generic) and as an entry in a class-lookup hash (ClassHash), and thus the class remained reachable through that constant after the response was discarded. Type and class are each 16-bit values, and thus an attacker controlling DNS responses (a spoofed response, or a malicious or hijacked upstream DNS server) has roughly 2^32 distinct (type, class) pairs to choose from. A single response of a few hundred kilobytes carrying tens of thousands of distinct unknown types permanently grows process memory by tens of megabytes; repeated responses accumulate without bound and are never reclaimed by garbage collection, because the constant keeps each class alive. Any code path that calls Resolv::DNS::Message.decode on attacker-influenced DNS responses is affected. resolv is a default gem, and thus this is reachable from a plain Ruby installation without any additional dependency.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80212"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-81690",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.39833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-59",
      "title": "verify-usb before 1.4.9 Symlink Directory Traversal Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81690"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-75005",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00485,
      "epss_percentile": 0.39683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-407",
      "title": "Apache APISIX: Unauthenticated CPU-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75005"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-74848",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00485,
      "epss_percentile": 0.39683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-444",
      "title": "Apache APISIX: Cross-user response poisoning in serverless plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74848"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-78257",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Booking and Rental Manager",
      "cwe": "CWE-502",
      "title": "WordPress Booking and Rental Manager plugin <= 2.7.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78257"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-81485",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00479,
      "epss_percentile": 0.39308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danielpopamd",
      "product": "linkedin-ads-mcp",
      "cwe": "CWE-22",
      "title": "danielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81485"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-81486",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00479,
      "epss_percentile": 0.39308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bsmi021",
      "product": "mcp-file-context-server",
      "cwe": "CWE-22",
      "title": "bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81486"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-81560",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00479,
      "epss_percentile": 0.39309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blackms",
      "product": "aistack",
      "cwe": "CWE-22",
      "title": "blackms aistack Static File server.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81560"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-81093",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apify",
      "product": "actors-mcp-server",
      "cwe": "CWE-918",
      "title": "Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeleton",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81093"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-74232",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.38979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zbtlink",
      "product": "L3_V2_8",
      "cwe": "CWE-300",
      "title": "Zbtlink MQWrt yunmgrd Cloud C2 Implant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74232"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-19313",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-122",
      "title": "Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19313"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-19318",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-121",
      "title": "Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19318"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-78274",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00465,
      "epss_percentile": 0.38348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "Fluent Boards Pro",
      "cwe": "CWE-434",
      "title": "WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78274"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-54687",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00459,
      "epss_percentile": 0.3791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DangerBlack",
      "product": "n8n-node-sqlite3",
      "cwe": "CWE-22",
      "title": "n8n-nodes-sqlite3: Path traversal via user-controlled database file path (db_path parameter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54687"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-19315",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.37826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-125",
      "title": "Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19315"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-81573",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.37724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "codemeter-runtime",
      "cwe": "CWE-284",
      "title": "Improper Access Control in Local-Only Configuration Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81573"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-32566",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.3732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ACPT",
      "product": "ACPT (Pro) - Custom Post Types Plugin for WordPress",
      "cwe": "CWE-266",
      "title": "WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32566"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-18965",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayRange",
      "product": "PayRange API",
      "cwe": "CWE-862",
      "title": "Missing Authorization in PayRange API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18965"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-13086",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-121",
      "title": "Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13086"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-81575",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "codemeter-runtime",
      "cwe": "CWE-130",
      "title": "Missing Sanity Checks for Buffer Lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81575"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-59285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00437,
      "epss_percentile": 0.36318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": null,
      "title": "Spring for GraphQL Unsafe Deserialization in pagination support",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59285"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-76179",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-598",
      "title": "Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76179"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-47727",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-94",
      "title": "Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass leading to EJS SSTI (Incomplete Fix of CVE-2026-45668)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47727"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-78271",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.35736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "FluentCRM Pro",
      "cwe": "CWE-266",
      "title": "WordPress FluentCRM Pro plugin <= 3.1.12 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78271"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-55758",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00427,
      "epss_percentile": 0.35429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cc-tweaked",
      "product": "CC-Tweaked",
      "cwe": "CWE-918",
      "title": "CC: Tweaked: Incomplete fix for GHSA-5jh9-2h63-pw4q: RFC 8215 NAT64 prefix (64:ff9b:1::/96) bypasses SSRF protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55758"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-81094",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00423,
      "epss_percentile": 0.35112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcp-router",
      "product": "mcp-router",
      "cwe": "CWE-306",
      "title": "mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81094"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-47884",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-22",
      "title": "Spring Framework Improper Path Limitation in XsltView",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47884"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-81335",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Baserow",
      "product": "Baserow",
      "cwe": "CWE-862",
      "title": "Baserow before 2.3.1 Unauthenticated Data Disclosure via Discarded Permission Check on Builder Data Sources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81335"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-54721",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silverstripe",
      "product": "silverstripe-userforms",
      "cwe": "CWE-94",
      "title": "Silverstripe UserForms: Remote code execution via userforms email subject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54721"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-77991",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00414,
      "epss_percentile": 0.34319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlaeventmanager.net",
      "product": "JEM - Joomla Event Manager extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77991"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-81707",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-20",
      "title": "openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81707"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-81491",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.33903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boxpositron",
      "product": "with-context-mcp",
      "cwe": "CWE-22",
      "title": "boxpositron with-context-mcp index.ts project_folder path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81491"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-81574",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.33792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "codemeter-runtime",
      "cwe": "CWE-134",
      "title": "Format String Vulnerability in Logger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81574"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-77018",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00406,
      "epss_percentile": 0.33576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Workeera",
      "cwe": "CWE-434",
      "title": "Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77018"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-5680",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-770",
      "title": "Undertow-core: undertow: denial of service via websocket permessage-deflate processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5680"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-61802",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-200",
      "title": "Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61802"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-66353",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.3241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "woylie",
      "product": "doggo",
      "cwe": "CWE-79",
      "title": "Doggo vulnerable to cross-site scripting via unescaped date field values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66353"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-81721",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-400",
      "title": "openssl_encrypt before 1.4.9 Denial of Service via KDF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81721"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-18885",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": null,
      "title": "Unauthenticated Remote Code Execution in GraphQL Composite Data API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18885"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-32479",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODEPRESS IT Solutions LLC",
      "product": "Visitor Traffic Real Time Statistics Pro",
      "cwe": "CWE-89",
      "title": "WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32479"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-78260",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ePayco",
      "product": "Epayco",
      "cwe": "CWE-89",
      "title": "WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78260"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-78288",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jonathan de Jong",
      "product": "Beautiful Taxonomy Filters",
      "cwe": "CWE-89",
      "title": "WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78288"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-80433",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "SureFeedback Client Site",
      "cwe": "CWE-862",
      "title": "WordPress SureFeedback Client Site plugin <= 1.2.12 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80433"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-81730",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-22",
      "title": "Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81730"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-59354",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware by Broadcom",
      "product": "Spring Security (OAuth2 Authorization Server module)",
      "cwe": "CWE-20",
      "title": "Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59354"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-79653",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.29848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse SW360",
      "cwe": "CWE-22",
      "title": "In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path traversal. The immediate workaround is to disable enable.attachment.store.to.file.system or update to fixed versions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79653"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-19223",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.29759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Smush",
      "cwe": "CWE-94",
      "title": "Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19223"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-59317",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00367,
      "epss_percentile": 0.29469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for Apache Kafka",
      "cwe": null,
      "title": "In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59317"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-76945",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-603",
      "title": "Ebyte NE2-D11 Use of Client-Side Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76945"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-54713",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00364,
      "epss_percentile": 0.29162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "queue",
      "cwe": "CWE-1023",
      "title": "CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54713"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-10036",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "speechbrain",
      "product": "speechbrain",
      "cwe": "CWE-502",
      "title": "SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.yaml Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10036"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-81673",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.28454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOOOLS",
      "product": "iSquad",
      "cwe": "CWE-89",
      "title": "Multiple Vulnerabilities in TOOOLS' iSquad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81673"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-76940",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-307",
      "title": "Ebyte NE2-D11 Improper Restriction of Excessive Authentication Attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76940"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-81699",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-770",
      "title": "openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81699"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-19092",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.27839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": "CWE-74",
      "title": "Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19092"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-81753",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.27922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-79",
      "title": "Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81753"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-76640",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unitree Robotics",
      "product": "G1 EDU",
      "cwe": "CWE-306",
      "title": "Unitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning Stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76640"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-59307",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": null,
      "title": "Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59307"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-81722",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.26992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-407",
      "title": "nltk PorterStemmer before 3.10.3 Quadratic-time DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81722"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-81692",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.26954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-789",
      "title": "openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81692"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-81693",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.26954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-789",
      "title": "openssl_encrypt before 1.4.9 Denial of Service via QR total field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81693"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-27330",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.2694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weptile",
      "product": "Mobile App for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Mobile App for WooCommerce plugin <= 0.4.62 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27330"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-81091",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcp-use",
      "product": "mcp-use",
      "cwe": "CWE-918",
      "title": "mcp-use Inspector Proxy Server-Side Request Forgery via Caller-Supplied Target URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81091"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-32550",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web, LLC",
      "product": "Kadence Shop Kit",
      "cwe": "CWE-89",
      "title": "WordPress Kadence Shop Kit plugin <= 3.0.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32550"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-32564",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ACPT",
      "product": "ACPT (Pro) - Custom Post Types Plugin for WordPress",
      "cwe": "CWE-89",
      "title": "WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32564"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-78285",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LikeBtn",
      "product": "Like Button Rating",
      "cwe": "CWE-89",
      "title": "WordPress Like Button Rating plugin <= 2.6.61 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78285"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-81277",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.26839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Suggestion Engine for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81277"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-59311",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.26856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": null,
      "title": "Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59311"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-81845",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arben-adm",
      "product": "mcp-sequential-thinking",
      "cwe": "CWE-22",
      "title": "arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81845"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-81837",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.25996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-22",
      "title": "RooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81837"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-81705",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.25877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-532",
      "title": "openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81705"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-67560",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bendix",
      "product": "EC80ESP+ J1708",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Bendix EC80 Brake ECU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67560"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-59284",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.2572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Commons",
      "cwe": null,
      "title": "Spring Cloud Commons no allow list for writable env actuator endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59284"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-54083",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.25507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-22",
      "title": "Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54083"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-81826",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00329,
      "epss_percentile": 0.25381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-384",
      "title": "Flowintel Fails to Invalidate Active Sessions After Password Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81826"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-78010",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-121",
      "title": "Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78010"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-81576",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "codemeter-runtime",
      "cwe": "CWE-639",
      "title": "Improper Authentication of Session Handles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81576"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-81678",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-918",
      "title": "AVideo SSRF Guard Bypass via IPv6 Transition Addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81678"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-30046",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30046"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-30047",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30047"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-30050",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-770",
      "title": "An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30050"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-30056",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30056"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-30057",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-770",
      "title": "An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30057"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-30062",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-770",
      "title": "An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30062"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-47886",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-400",
      "title": "Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47886"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-47888",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.24822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-401",
      "title": "Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47888"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-6876",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.24726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "Now Platform",
      "cwe": null,
      "title": "Sandbox Escape in Now Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6876"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-78617",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.24597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-203",
      "title": "WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78617"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-19314",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.24495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-191",
      "title": "Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Service (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19314"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-19316",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.24495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-415",
      "title": "Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19316"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-19317",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.24495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-125",
      "title": "Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Service (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19317"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-78009",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.24495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-125",
      "title": "Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78009"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-78011",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.24494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-191",
      "title": "Fireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Service (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78011"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-81101",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.24492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Airtable",
      "product": "airtable-mcp-cli",
      "cwe": "CWE-200",
      "title": "Airtable MCP CLI before 0.2.5 Credential Disclosure via Unvalidated Configured Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81101"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-81743",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-22",
      "title": "Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81743"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-80213",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.2415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruby",
      "product": "resolv",
      "cwe": "CWE-197",
      "title": "An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but the label data was written unchanged, and thus the bytes on the wire described a different name than the one the application asked to encode. RFC 1035 section 2.3.4 limits a label to 63 octets, and the two high bits of the length octet are reserved for compression pointers. put_string packed the length with put_pack(\"C\", d.length) and put_label used it for labels, and thus any value from 0 to 255 could end up as a label length octet, including the reserved 0x40-0xBF range and the 0xC0-0xFF pointer range. Resolv::DNS::Name.create did not check per-label or total name length either, and thus an attacker-controlled hostname reached the encoder unchanged. An application that resolves an attacker-controlled hostname sends a query whose wire bytes name a domain the attacker chose. A hostname suffix that the application validates against an allowlist becomes padding that never appears on the wire, and thus allowlist and egress checks can be bypassed. The recursive resolver caches the response under the attacker's name, and DNS logs record that name rather than the one the application asked for. A label length whose low octet lands in the 0xC0-0xFF range produces a length octet that conforming parsers read as the start of a compression pointer, with the following attacker-controlled byte as the offset.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80213"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-81719",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.23867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-94",
      "title": "openssl_encrypt before 1.4.9 Remote Code Execution via Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81719"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-47894",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.23909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Config",
      "cwe": null,
      "title": "Spring Cloud Config Server Native Environment Repository Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47894"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-47890",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.23655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-93",
      "title": "Spring Framework Server Sent Event stream corruption while rendering fragments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47890"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-80208",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apitable",
      "product": "apitable",
      "cwe": "CWE-306",
      "title": "APITable through 1.13.0-beta.1 Missing Authentication on the Internal Account Closure Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80208"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-81662",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-20",
      "title": "Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configuration Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81662"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-78008",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-787",
      "title": "Fireware OS Authenticated Buffer Overflow in wgagent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78008"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-81818",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-269",
      "title": "Flowintel Organization Administrator Can Reset Full Administrator Password and Escalate Privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81818"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-81272",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "FluentPlayer Pro",
      "cwe": "CWE-862",
      "title": "WordPress FluentPlayer Pro plugin <= 1.3.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81272"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-78174",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.23015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-200",
      "title": "WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78174"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-81701",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.2297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-347",
      "title": "openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81701"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-26897",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00306,
      "epss_percentile": 0.22791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26897"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-81676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOOOLS",
      "product": "iSquad",
      "cwe": "CWE-89",
      "title": "Multiple Vulnerabilities in TOOOLS' iSquad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81676"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-82072",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82072"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-81659",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-22",
      "title": "Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81659"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-54732",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elwerene",
      "product": "libreoffice-convert",
      "cwe": "CWE-22",
      "title": "libreoffice-convert: path traversal / arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54732"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-75419",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.21956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users, resetting passwords, and creating tenants.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75419"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-59271",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.21759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AMQP",
      "cwe": "CWE-209",
      "title": "Admin password disclosed in BrokerNotAliveException message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59271"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-75418",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.21739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sequences to read arbitrary files accessible to the process, disclosing sensitive information such as system files and deployment configuration files containing credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75418"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-81827",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.21705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-20",
      "title": "Flowintel Login Email Validation Bypass Allows Log Injection via Crafted Email Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81827"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-65931",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-862",
      "title": "LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65931"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-59315",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Config",
      "cwe": null,
      "title": "Spring Cloud Config Monitor Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59315"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-81819",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-862",
      "title": "Flowintel Missing Authorization Allows Regular API Users to View Other Users’ Task Assignments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81819"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-81664",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openfaas",
      "product": "faas",
      "cwe": "CWE-306",
      "title": "OpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /system/telemetry Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81664"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-47891",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-770",
      "title": "Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47891"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-59270",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": null,
      "title": "Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59270"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-19225",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.20991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Defender Security",
      "cwe": "CWE-94",
      "title": "Defender Security < 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Multisite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19225"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-59320",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.20977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AMQP",
      "cwe": null,
      "title": "In Spring AMQP the link credit never replenished on listener exception path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59320"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-77358",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.20737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yhirose",
      "product": "cpp-httplib",
      "cwe": "CWE-416",
      "title": "cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_close()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77358"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-81931",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.20713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-434",
      "title": "Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81931"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-81679",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openremote",
      "product": "openremote",
      "cwe": "CWE-200",
      "title": "OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81679"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-80207",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.2063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apitable",
      "product": "apitable",
      "cwe": "CWE-306",
      "title": "APITable through 1.13.0-beta.1 Missing Authentication on the Internal Notification Create Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80207"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-80209",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.20671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fonoster",
      "product": "fonoster",
      "cwe": "CWE-863",
      "title": "Fonoster through 0.22.7 Incorrect Authorization in the Identity UpdateWorkspace Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80209"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-81698",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.20489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-78",
      "title": "openssl_encrypt before 1.4.9 Shell Injection via info command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81698"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-81672",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOOOLS",
      "product": "iSquad",
      "cwe": "CWE-89",
      "title": "Multiple Vulnerabilities in TOOOLS' iSquad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81672"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-81674",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOOOLS",
      "product": "iSquad",
      "cwe": "CWE-89",
      "title": "Multiple Vulnerabilities in TOOOLS' iSquad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81674"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-81274",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metaphorcreations",
      "product": "Ditty",
      "cwe": "CWE-862",
      "title": "WordPress Ditty plugin <= 3.1.67 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81274"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-81276",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Kali Forms",
      "cwe": "CWE-862",
      "title": "WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81276"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-78137",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "StoreGrowth",
      "cwe": "CWE-862",
      "title": "StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78137"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-78333",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.19579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "12 Step Meeting List",
      "cwe": "CWE-79",
      "title": "12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode Event Log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78333"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-53580",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-73",
      "title": "Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53580"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-47881",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Batch",
      "cwe": "CWE-400",
      "title": "Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47881"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-81525",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "PHP Library",
      "cwe": "CWE-943",
      "title": "Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81525"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-77341",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yhirose",
      "product": "cpp-httplib",
      "cwe": "CWE-93",
      "title": "cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77341"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-37006",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0027,
      "epss_percentile": 0.18767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37006"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-47849",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data REST",
      "cwe": "CWE-915",
      "title": "Spring Data REST allows mutation of identifier and version properties via JSON Patch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47849"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-5706",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.1842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "BT Mesh SDK",
      "cwe": "CWE-130",
      "title": "Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5706"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-81522",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C++ Driver",
      "cwe": "CWE-116",
      "title": "Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81522"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-81726",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-73",
      "title": "NLTK through 3.10.3 Path Traversal via Model-Artifact APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81726"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-18886",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00264,
      "epss_percentile": 0.17963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": null,
      "title": "Unauthenticated Privilege Escalation via System Configuration Image Upload Processor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18886"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-75159",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.17924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-415",
      "title": "MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75159"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-30612",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00264,
      "epss_percentile": 0.17937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30612"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-79988",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-693",
      "title": "Authenticated RCE through Twig sandbox escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79988"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-47885",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-770",
      "title": "Spring Framework maxPartSize Ignored in PartEventHttpMessageReader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47885"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-81724",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-674",
      "title": "NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81724"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-77989",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlaeventmanager.net",
      "product": "JEM - Joomla Event Manager extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77989"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-37007",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00258,
      "epss_percentile": 0.17247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37007"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-75357",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00258,
      "epss_percentile": 0.17248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75357"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-68929",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-862",
      "title": "FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68929"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-13415",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.1707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CMP",
      "cwe": "CWE-269",
      "title": "CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13415"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-68967",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bendix",
      "product": "EC80ESP+ J1708",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Bendix EC80 Brake ECU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68967"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-59276",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-208",
      "title": "Timing Attack via Non-Constant-Time Comparison of Sensitive Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59276"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-78103",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-841",
      "title": "Dimension Log Server Configuration Lock Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78103"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-81728",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.16936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-89",
      "title": "Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81728"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-19715",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.16966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP OAuth Server ( Login with WordPress )",
      "cwe": "CWE-200",
      "title": "WP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosure via Debug Log File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19715"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-81814",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.1691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-79",
      "title": "Flowintel Stored XSS in Calendar via Malicious Case Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81814"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-75813",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.16851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-862",
      "title": "Ebyte NE2-D11 Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75813"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-16279",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00254,
      "epss_percentile": 0.16644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "3DSwymer",
      "cwe": "CWE-285",
      "title": "Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16279"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-81700",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00254,
      "epss_percentile": 0.16646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-347",
      "title": "openssl_encrypt before 1.4.9 GPG Signature Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81700"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-78618",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-284",
      "title": "Dimension Business Logic Flaw Allows Chained Backend Object Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78618"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-19454",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetBackup",
      "cwe": "CWE-863",
      "title": "JetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19454"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-81675",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOOOLS",
      "product": "iSquad",
      "cwe": "CWE-89",
      "title": "Multiple Vulnerabilities in TOOOLS' iSquad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81675"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-13108",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-400",
      "title": "Dimension Denial-of-Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13108"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-47889",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-1275",
      "title": "Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47889"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-59294",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": null,
      "title": "Arbitrary File Write via Path Traversal in ResourceCacheService",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59294"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-80179",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-770",
      "title": "Jwcrypto: jwcrypto: denial of service via malformed jwe tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80179"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-81820",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-79",
      "title": "Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81820"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-81677",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOOOLS",
      "product": "iSquad",
      "cwe": "CWE-89",
      "title": "Multiple Vulnerabilities in TOOOLS' iSquad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81677"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-77017",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Workeera",
      "cwe": "CWE-200",
      "title": "Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via Candidate Profile Mass Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77017"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-47875",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.15948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Batch",
      "cwe": "CWE-502",
      "title": "JobParameterDeserializer bypasses the trusted-type allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47875"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-47878",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.15947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Batch",
      "cwe": "CWE-502",
      "title": "Unsafe Java deserialization in DefaultExecutionContextSerializer without class allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47878"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-37004",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00248,
      "epss_percentile": 0.15934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37004"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-78615",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.15756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-79",
      "title": "WatchGuard Dimension Reflected DOM-Based XSS in Report Detail Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78615"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-81851",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.15623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-122",
      "title": "Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81851"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-59275",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.15697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AMQP",
      "cwe": "CWE-502",
      "title": "Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59275"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-80211",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FrontAccounting",
      "product": "FrontAccounting",
      "cwe": "CWE-916",
      "title": "FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80211"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-47879",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Gateway",
      "cwe": "CWE-918",
      "title": "Spring Cloud Gateway SSRF and native file access with gRPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47879"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-4398",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4398"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-77016",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Workeera",
      "cwe": "CWE-73",
      "title": "Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77016"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-77438",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-200",
      "title": "Trilium unauthenticated share-search discloses password-protected and hidden shared notes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77438"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-11754",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.14953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Seres Software",
      "product": "syWEB",
      "cwe": "CWE-203",
      "title": "User Enumeration in Seres Software's syWEB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11754"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-69658",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00239,
      "epss_percentile": 0.14808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-319",
      "title": "Ebyte NE2-D11 Cleartext Transmission of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69658"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-61783",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.14774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-200",
      "title": "Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61783"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-77034",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.14851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlaeventmanager.net",
      "product": "JEM - Joomla Event Manager extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77034"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-74820",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00238,
      "epss_percentile": 0.14642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": null,
      "title": "Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74820"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-34674",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.14683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Substance 3D Sampler",
      "cwe": "CWE-122",
      "title": "Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34674"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-59324",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": null,
      "title": "fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59324"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-78261",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Realtyna",
      "product": "Realtyna Organic IDX plugin",
      "cwe": "CWE-79",
      "title": "WordPress Realtyna Organic IDX plugin plugin <= 5.4.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78261"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-78281",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "CP Media Player",
      "cwe": "CWE-79",
      "title": "WordPress CP Media Player plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78281"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-78283",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Music Player for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78283"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-78289",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LoftOcean",
      "product": "CozyStay",
      "cwe": "CWE-79",
      "title": "WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78289"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-78293",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axew3",
      "product": "WP w3all phpBB",
      "cwe": "CWE-79",
      "title": "WordPress WP w3all phpBB plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78293"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-71396",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.1444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bendix",
      "product": "EC80ESP+ J1708",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in Bendix EC80 Brake ECU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71396"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-54085",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-88",
      "title": "Wazuh: Missing input validation in multiple active response scripts allows argument injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54085"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-59274",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-409",
      "title": "Unbounded decompression in UnZipTransformer enables zip-bomb DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59274"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-81847",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MAA-AI",
      "product": "MaaMCP",
      "cwe": "CWE-22",
      "title": "MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81847"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-81834",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00234,
      "epss_percentile": 0.14095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-74",
      "title": "RooCodeInc Roo-Code README File ExecaTerminalProcess code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81834"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-59280",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.13838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-22",
      "title": "Spring Framework Path Traversal via Backslash in SpringTemplateLoader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59280"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-78047",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.1366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-79",
      "title": "Dimension Stored XSS in Scheduled Report Task",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78047"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-77977",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-306",
      "title": "Ebyte NE2-D11 Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77977"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-77035",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlaeventmanager.net",
      "product": "JEM - Joomla Event Manager extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77035"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-78498",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-918",
      "title": "Dimension Server-Side Request Forgery via Email Server Test Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78498"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-78499",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-918",
      "title": "Dimension SSRF via FTP Server Test Connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78499"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-78500",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-208",
      "title": "Dimension Blind SSRF via Database Test Connection Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78500"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-59355",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Spring Authorization Server",
      "cwe": "CWE-601",
      "title": "Spring Authorization Server: Open Redirect via request_uri parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59355"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-37009",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00226,
      "epss_percentile": 0.13175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37009"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-81723",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-400",
      "title": "NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81723"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-81725",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-400",
      "title": "NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81725"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-59293",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": null,
      "title": "SMB minimum protocol dialect defaults to SMB1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59293"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-36102",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00221,
      "epss_percentile": 0.1245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36102"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-37012",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00221,
      "epss_percentile": 0.12449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37012"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-81729",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-863",
      "title": "Dolibarr before 23.0.4 Incorrect Authorization on REST API Document Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81729"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-81279",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Murali",
      "product": "Push Notification for Post and BuddyPress",
      "cwe": "CWE-862",
      "title": "WordPress Push Notification for Post and BuddyPress plugin <= 3.20 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81279"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-75889",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Alloy",
      "cwe": null,
      "title": "CVE-2026-75889 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75889"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-18717",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.1183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Applied Systems Engineering",
      "product": "ASE2000 V2",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation in ASE 2000",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18717"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-59319",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.11679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": null,
      "title": "RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59319"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-17562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.11678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Summit Security Systems",
      "product": "AdisyonPro",
      "cwe": "CWE-639",
      "title": "IDOR in Zirve Security's AdisyonPro",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17562"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-48996",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00213,
      "epss_percentile": 0.11511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-79",
      "title": "Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48996"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-53578",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00213,
      "epss_percentile": 0.11511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-79",
      "title": "Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53578"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-53579",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00213,
      "epss_percentile": 0.1151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-79",
      "title": "Trilium: Note Import to RCE via Book Note",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53579"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-59306",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00213,
      "epss_percentile": 0.11505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Stream",
      "cwe": null,
      "title": "Potential for deserialization of untrusted types in Spring Cloud Stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59306"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-81658",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-639",
      "title": "Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81658"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-78273",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "Fluent Boards Pro",
      "cwe": "CWE-79",
      "title": "WordPress Fluent Boards Pro plugin <= 2.0.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78273"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-81687",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.10923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-400",
      "title": "openssl_encrypt before 1.4.9 Denial of Service via KDF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81687"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-59277",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00208,
      "epss_percentile": 0.10869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-693",
      "title": "Spring Security InetAddressMatchers Incomplete Internal Network Classification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59277"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-81817",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.10752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-639",
      "title": "Flowintel Missing Task-to-Case Authorization Allows Cross-Case Task Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81817"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-77990",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.10752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlaeventmanager.net",
      "product": "JEM - Joomla Event Manager extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77990"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-78495",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.1075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-918",
      "title": "Dimension Server-Side Request Forgery via Remote Backup Connection Test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78495"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-59322",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": null,
      "title": "EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59322"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-78125",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": "CWE-200",
      "title": "LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78125"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-79718",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netron",
      "product": "Netron",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79718"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-79719",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netron",
      "product": "Netron",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79719"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-79720",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netron",
      "product": "Netron",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79720"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-81581",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "wibukey",
      "cwe": "CWE-119",
      "title": "User input in WibuKey is used (without proper sanitization) to compute the address of a pointer, which can be exploited to let the user point to any storage, to which Windows responds with a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81581"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-81521",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "GO Driver",
      "cwe": "CWE-99",
      "title": "Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81521"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-81526",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Rust Driver",
      "cwe": "CWE-74",
      "title": "Cross-database write redirection via unvalidated dotted database name in bulk write namespaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81526"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-81688",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-311",
      "title": "openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81688"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-81689",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-916",
      "title": "openssl_encrypt before 1.4.9 Weak Pepper Key Derivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81689"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-81691",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-319",
      "title": "openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81691"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-81704",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-916",
      "title": "openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81704"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-81848",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberchitta",
      "product": "scrapling-fetch-mcp",
      "cwe": "CWE-918",
      "title": "cyberchitta scrapling-fetch-mcp _fetcher.py s_fetch_pattern server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81848"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-16567",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Document Embedder",
      "cwe": "CWE-639",
      "title": "Document Embedder < 2.3.1 - Unauthenticated Private Document Download via Token Oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16567"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-81716",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.08873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-22",
      "title": "openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81716"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-19889",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.08768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab AI Gateway",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in GitLab AI Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19889"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-75871",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.08769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab AI Gateway",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in GitLab AI Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75871"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-37066",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37066"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-47892",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": null,
      "title": "Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47892"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-81715",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-532",
      "title": "openssl_encrypt before 1.4.9 Credential Exposure via Debug Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81715"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-47877",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-79",
      "title": "Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47877"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2025-62342",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "IEM",
      "cwe": "CWE-613",
      "title": "HCL IntelliOps Event Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62342"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-81836",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-319",
      "title": "RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81836"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-47883",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-601",
      "title": "Spring Framework Open Redirect in UrlHandlerFilter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47883"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-59316",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Authorization Server",
      "cwe": null,
      "title": "Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59316"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-81271",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-352",
      "title": "WordPress GeoDirectory plugin <= 2.8.176 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81271"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2025-62343",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00184,
      "epss_percentile": 0.08037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL IEM",
      "cwe": "CWE-557",
      "title": "HCL IntelliOps Event Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62343"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-81527",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C# Driver",
      "cwe": "CWE-943",
      "title": "NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81527"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-47880",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-20",
      "title": "DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders without excluding framework-significant names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47880"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-71401",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "wicked",
      "cwe": "CWE-191",
      "title": "wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71401"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-30067",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00182,
      "epss_percentile": 0.07838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30067"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-30072",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00182,
      "epss_percentile": 0.07838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30072"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-30073",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00182,
      "epss_percentile": 0.07838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30073"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-54330",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ceph",
      "product": "ceph",
      "cwe": "CWE-347",
      "title": "Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54330"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-5738",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BilPark Informatics Technologies Industry and Trade Inc.",
      "product": "DoXBASE",
      "cwe": "CWE-79",
      "title": "Reflected XSS in BilPark's DoXBASE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5738"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-11747",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Seres Software",
      "product": "syWEB",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Seres Software's syWEB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11747"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-26899",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.07397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26899"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-30045",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.07379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30045"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-81685",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00177,
      "epss_percentile": 0.07328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-116",
      "title": "openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81685"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-81694",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00177,
      "epss_percentile": 0.07328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-117",
      "title": "verify-usb before 1.4.9 Output Injection via Unsanitized Filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81694"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-81695",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00177,
      "epss_percentile": 0.07329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-117",
      "title": "openssl_encrypt before 1.4.9 Terminal Injection via key_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81695"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-81696",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00177,
      "epss_percentile": 0.07328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-117",
      "title": "openssl_encrypt before 1.4.9 Terminal Injection via info Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81696"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-75814",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-352",
      "title": "Ebyte NE2-D11 Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75814"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-78138",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.0721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Finale Lite",
      "cwe": "CWE-200",
      "title": "Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78138"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-81273",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.06954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "FluentBooking Pro",
      "cwe": "CWE-352",
      "title": "WordPress FluentBooking Pro plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81273"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-81529",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.06968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C# Driver",
      "cwe": "CWE-88",
      "title": "Connection-option injection via unescaped settings in the canonical MongoDB URL builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81529"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-66155",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.06984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Element maps-ng V47",
      "cwe": "CWE-79",
      "title": "A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66155"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-59281",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": null,
      "title": "Spring Framework Cross-site Scripting via EscapedErrors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59281"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-81097",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maquina-app",
      "product": "rails-mcp-server",
      "cwe": "CWE-78",
      "title": "rails-mcp-server 1.4.0 through 1.6.0 OS Command Execution via execute_ruby PTY Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81097"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-47887",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-601",
      "title": "Spring Framework Open Redirect in UrlFileNameViewController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47887"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-26452",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26452"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-26456",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the request dispatch thread and the session cleanup thread when accessing shared session list nodes without proper synchronization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26456"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-26459",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26459"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-75548",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-1021",
      "title": "Ebyte NE2-D11 Improper Restriction of Rendered UI Layers or Frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75548"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-81731",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-79",
      "title": "Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81731"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-81835",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-94",
      "title": "RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81835"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-81833",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.06621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-74",
      "title": "RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81833"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-39944",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ceph",
      "product": "ceph",
      "cwe": "CWE-327",
      "title": "Ceph: CephX AES Authentication error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39944"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-71402",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "wicked",
      "cwe": "CWE-125",
      "title": "wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71402"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-37198",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37198"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-73809",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-319",
      "title": "Ebyte NE2-D11 Cleartext Transmission of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73809"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-81703",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-287",
      "title": "openssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81703"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-81572",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "codemeter-runtime",
      "cwe": "CWE-59",
      "title": "Local Privilege Escalation in CodeMeter Runtime on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81572"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-81092",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mark3labs",
      "product": "mcp-go",
      "cwe": "CWE-346",
      "title": "mcp-go before 0.56.0 Missing Host Header Validation Enables DNS Rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81092"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-81528",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.05806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C# Driver",
      "cwe": "CWE-943",
      "title": "NoSQL injection via array replacement bypassing update shape validation in driver write path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81528"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-78616",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.05873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-79",
      "title": "Dimension Stored XSS via Trusted CA Certificate Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78616"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-5218",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.05882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softtr Informatics Technology Trading Limited Company",
      "product": "E-Commerce Pack",
      "cwe": "CWE-80",
      "title": "HTML Injection in Softtr's E-Commerce Pack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5218"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-59272",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AMQP",
      "cwe": "CWE-297",
      "title": "Log4j2 AmqpAppender disables TLS hostname verification by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59272"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-34616",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe DNG Software Development Kit (SDK)",
      "cwe": "CWE-125",
      "title": "DNG SDK | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34616"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-37067",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00163,
      "epss_percentile": 0.05742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37067"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-37069",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00163,
      "epss_percentile": 0.05743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37069"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-37073",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00163,
      "epss_percentile": 0.05742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37073"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-59313",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00163,
      "epss_percentile": 0.05784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": null,
      "title": "Server Sent Event stream corruption in Spring MVC functional web framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59313"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-59314",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00163,
      "epss_percentile": 0.05783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": null,
      "title": "Spring Framework response splitting in ContentDisposition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59314"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-50152",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00162,
      "epss_percentile": 0.05693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ceph",
      "product": "ceph",
      "cwe": "CWE-285",
      "title": "Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50152"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-80210",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FrontAccounting",
      "product": "FrontAccounting",
      "cwe": "CWE-352",
      "title": "FrontAccounting through 2.4.20 Cross-Site Request Forgery on Financial Transaction Forms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80210"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-16568",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce",
      "cwe": "CWE-639",
      "title": "ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16568"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-37064",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00162,
      "epss_percentile": 0.05699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37064"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-16895",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Metasploit-framework",
      "cwe": "CWE-305",
      "title": "Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16895"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-81095",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.0547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timescale",
      "product": "pg-aiguide",
      "cwe": "CWE-346",
      "title": "Timescale pg-aiguide through 0.5.0 DNS Rebinding via Disabled Host Header Allow-List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81095"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-81099",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timescale",
      "product": "tiger-slack",
      "cwe": "CWE-346",
      "title": "Timescale tiger-slack DNS Rebinding via Disabled Host Header Allow-List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81099"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-81100",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timescale",
      "product": "tiger-gh-mcp-server",
      "cwe": "CWE-346",
      "title": "Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81100"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-59298",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0016,
      "epss_percentile": 0.05479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": null,
      "title": "Potential for improper filtering of HTTP headers in Spring Cloud Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59298"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-59278",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for Apache Kafka",
      "cwe": "CWE-918",
      "title": "In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59278"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-17610",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "SiSDK",
      "cwe": "CWE-404",
      "title": "RAIL 802.15.4 Mux missing ACK can lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17610"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-59291",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": null,
      "title": "Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59291"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-37065",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00159,
      "epss_percentile": 0.05346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37065"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-59283",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00159,
      "epss_percentile": 0.05311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": null,
      "title": "Spring Framework Safety Guard Bypass via SpEL Expression Compilation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59283"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-81579",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wibu-systems-ag",
      "product": "wibukey",
      "cwe": "CWE-123",
      "title": "An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81579"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-81524",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-99",
      "title": "Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81524"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-37068",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37068"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-37070",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37070"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-37071",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37071"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-37072",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37072"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-59289",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": null,
      "title": "Spring for GraphQL Denial of Service via pagination support",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59289"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-81680",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.04914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-347",
      "title": "openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81680"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-26453",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string \"separate\", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26453"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-26457",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when processing COAP messages containing options with zero length.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26457"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-73839",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-522",
      "title": "Ebyte NE2-D11 Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73839"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-56652",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scottchiefbaker",
      "product": "dool",
      "cwe": "CWE-1236",
      "title": "Formula Injection in dool project",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56652"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-16569",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce",
      "cwe": "CWE-284",
      "title": "ShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16569"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-78139",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Notifima",
      "cwe": "CWE-639",
      "title": "Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78139"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-56651",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scottchiefbaker",
      "product": "dool",
      "cwe": "CWE-59",
      "title": "Arbitrary File Overwrite via Symlink Following in dool project",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56651"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-38347",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00152,
      "epss_percentile": 0.04643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38347"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-18374",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-787",
      "title": "Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18374"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-59299",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": null,
      "title": "Composition lookup can potentially poison base function in Spring Cloud Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59299"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-59300",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": null,
      "title": "Potential for logging sensitive data in Spring Cloud Function AWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59300"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-59301",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": null,
      "title": "Potential for logging sensitive data in Spring Cloud Function Azure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59301"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-59302",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Stream",
      "cwe": null,
      "title": "Potential for logging sensitive data in Spring Cloud Stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59302"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-59303",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Stream",
      "cwe": null,
      "title": "Dynamic destination cache size is not properly bound in Spring Cloud Stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59303"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-59304",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Stream",
      "cwe": null,
      "title": "Improper caching of the original content type in Spring Cloud Stream Avro",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59304"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-59305",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Stream",
      "cwe": null,
      "title": "Partition interceptor may be improperly added while sending message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59305"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-38343",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0015,
      "epss_percentile": 0.04497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38343"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-81697",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.0442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-426",
      "title": "openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81697"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-30051",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PUT request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30051"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-30058",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.0444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30058"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-30059",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30059"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-30060",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30060"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-30063",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.0444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30063"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-30064",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30064"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-30068",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30068"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-30069",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30069"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-30070",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30070"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-30071",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30071"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-38344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38344"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-38345",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38345"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-38346",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38346"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-38348",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38348"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-38349",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38349"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-38350",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38350"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-59282",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.0444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": null,
      "title": "Spring Framework Denial of Service via Unbounded List Growth in Data Binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59282"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-59287",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": null,
      "title": "Spring for GraphQL WebSocket Client Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59287"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-59288",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": null,
      "title": "Spring for GraphQL Information Exposure in GraphiQL support",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59288"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-75337",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75337"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-75339",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00149,
      "epss_percentile": 0.04445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75339"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-75417",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00148,
      "epss_percentile": 0.04345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injection, potentially leading to full database compromise.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75417"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-78610",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-352",
      "title": "Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78610"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-64896",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "T2000",
      "cwe": "CWE-284",
      "title": "T2000 open debug port",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64896"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-59292",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00144,
      "epss_percentile": 0.03957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": null,
      "title": "World-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59292"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-81668",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.03887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-639",
      "title": "Rubygem-katello: cross-tenant content view filter rule access and modification via unauthorized parent filter lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81668"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-34620",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe DNG Software Development Kit (SDK)",
      "cwe": "CWE-787",
      "title": "DNG SDK | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34620"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-13414",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CMP",
      "cwe": "CWE-862",
      "title": "CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13414"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-13416",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CMP",
      "cwe": "CWE-79",
      "title": "CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13416"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-81102",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dropbox",
      "product": "mcp-server-dash",
      "cwe": "CWE-346",
      "title": "Dropbox Dash MCP Server DNS Rebinding via Missing Host Header Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81102"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-81702",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00139,
      "epss_percentile": 0.03551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-345",
      "title": "openssl_encrypt before 1.4.9 Key Substitution via Identity Load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81702"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-81714",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00139,
      "epss_percentile": 0.03541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-347",
      "title": "openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81714"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-47893",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": null,
      "title": "Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketService",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47893"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-81727",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-59",
      "title": "NLTK before 3.10.3 Hardlink File Overwrite via downloader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81727"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-81838",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aws",
      "product": "diagram-as-code",
      "cwe": "CWE-23",
      "title": "Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81838"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-81706",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00132,
      "epss_percentile": 0.03025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-345",
      "title": "openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81706"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-81681",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00131,
      "epss_percentile": 0.02972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-311",
      "title": "openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81681"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-81718",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.02972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-326",
      "title": "openssl_encrypt before 1.4.9 Weak Cryptographic Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81718"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-81334",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.02903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hank-ai",
      "product": "darknet",
      "cwe": "CWE-125",
      "title": "darknet through 6.0 Out-of-Bounds Read and Write via Unchecked Layer Index in .cfg Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81334"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-81720",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-400",
      "title": "openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81720"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-59321",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": null,
      "title": "Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59321"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-81684",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-214",
      "title": "openssl_encrypt before 1.4.9 Information Disclosure via Command Line",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81684"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-81682",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-276",
      "title": "openssl_encrypt before 1.4.9 Insecure File Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81682"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-81686",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-20",
      "title": "openssl_encrypt before 1.4.9 D-Bus Properties Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81686"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-54084",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-476",
      "title": "Wazuh agent enrollment NULL pointer dereference via malformed manager response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54084"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-59286",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00114,
      "epss_percentile": 0.01629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": null,
      "title": "Spring for GraphQL loads Untrusted Resources in GraphiQL support",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59286"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-19398",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.0148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "FA507NV",
      "cwe": "CWE-787",
      "title": "“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' Security Update for ASUS FA507NV / FA507NU BIOS ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19398"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-81893",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81893"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-44629",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00105,
      "epss_percentile": 0.01162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genetec Inc.",
      "product": "Synergis Softwire",
      "cwe": "CWE-922",
      "title": "Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44629"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-76549",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "UpdraftPlus: WP Backup & Migration Plugin",
      "cwe": "CWE-352",
      "title": "UpdraftPlus < 1.26.7 - Backup Restoration via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76549"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2025-30156",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ceph",
      "product": "ceph",
      "cwe": "CWE-327",
      "title": "Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30156"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-81717",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00091,
      "epss_percentile": 0.00555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-347",
      "title": "openssl_encrypt before 1.4.9 Integrity Bypass via Added Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81717"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-75573",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-532",
      "title": "MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are Supplied",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75573"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-25250",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eazsolution",
      "product": "EazyFix",
      "cwe": "CWE-325",
      "title": "EAZ EazyFix 12.9 allows a Security Feature Bypass related to a \"Missing Cryptographic Step\" associated with \"Secure Boot disable.\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25250"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-59297",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00084,
      "epss_percentile": 0.00297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": null,
      "title": "Spring Cloud Function can incorrectly determine if URI is secure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59297"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-81523",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00074,
      "epss_percentile": 0.00077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "libmongocrypt",
      "cwe": "CWE-74",
      "title": "Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocrypt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81523"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-81530",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00066,
      "epss_percentile": 0.00021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C# Driver",
      "cwe": "CWE-532",
      "title": "KMS master key exposure via unredacted credential serialization in driver settings string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81530"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-81683",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00057,
      "epss_percentile": 0.00004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jahlives",
      "product": "openssl_encrypt",
      "cwe": "CWE-312",
      "title": "openssl_encrypt before 1.4.9 Plaintext Private Key Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81683"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-19854",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00053,
      "epss_percentile": 0.00002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Clickhouse Datasource",
      "cwe": "CWE-319",
      "title": "CVE-2026-19854 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19854"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2023-49105",
      "detail": "ADDED TO KEV — CVE-2023-49105. Remediation due August 30, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-53362",
      "detail": "ADDED TO KEV — CVE-2026-53362 (Linux). Remediation due August 30, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-66384",
      "detail": "ADDED TO KEV — CVE-2026-66384 (jfrog artifactory). Remediation due September 10, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-23758",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-23758 (AjaxPro.2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-0995",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-0995 (kernel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13598",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13598 (Unknown RestrictMate). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18252",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18252 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41035",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44902",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44902 (open-telemetry opentelemetry-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56121",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56121 (feast-dev feast). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62383",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62383 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62388",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62388 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63311",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63311 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66393",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66393 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78435",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78435 (Faveo Helpdesk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78638",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78638 (peerigon unzip-crx). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79623",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79623 (FishCodeTech Muteki). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79911",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79911 (TOTOLINK N600R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81202",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81202 (itsourcecode Payroll System). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2021-23758",
      "detail": "RESCORED — CVE-2021-23758 (AjaxPro.2). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10573",
      "detail": "RESCORED — CVE-2026-10573 (Rockwell Automation 1734 POINT I/O). CVSS 8.7 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-13097",
      "detail": "RESCORED — CVE-2026-13097 (Red Hat Enterprise Linux 10). CVSS 9.1 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58092",
      "detail": "RESCORED — CVE-2026-58092 (FreeBSD). CVSS 5.4 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58095",
      "detail": "RESCORED — CVE-2026-58095 (FreeBSD). CVSS 9.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58096",
      "detail": "RESCORED — CVE-2026-58096 (FreeBSD). CVSS 9.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65660",
      "detail": "RESCORED — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66299",
      "detail": "RESCORED — CVE-2026-66299 (Apache Software Foundation Apache Tomcat). CVSS 7.5 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78983",
      "detail": "RESCORED — CVE-2026-78983 (Google Chrome). CVSS 9.6 → 8.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79054",
      "detail": "RESCORED — CVE-2026-79054 (Google Chrome). CVSS 9.6 → 8.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79210",
      "detail": "RESCORED — CVE-2026-79210 (Google Chrome). CVSS 9.6 → 8.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79224",
      "detail": "RESCORED — CVE-2026-79224 (Google Chrome). CVSS 9.6 → 8.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81421",
      "detail": "RESCORED — CVE-2026-81421 (ddfourtwo sentry-selfhosted-mcp). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15538",
      "detail": "PATCH SHIPPED — CVE-2026-15538 (primefaces primereact). Fixed in primereact 10.9.9."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-34621",
      "detail": "PATCH SHIPPED — CVE-2026-34621 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21411."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
