{
  "day": "2026-08-28",
  "boundary": "UTC calendar day",
  "published_count": 496,
  "by_severity": {
    "CRITICAL": 49,
    "HIGH": 184,
    "MEDIUM": 126,
    "LOW": 16
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 121,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-38820",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.01743,
      "epss_percentile": 0.75813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openNDS",
      "product": "openNDS",
      "cwe": "CWE-78",
      "title": "openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38820"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-82082",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01497,
      "epss_percentile": 0.71956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Green-Computing",
      "product": "NUMail",
      "cwe": "CWE-78",
      "title": "Green-Computing｜NUMail - OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82082"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-38822",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00849,
      "epss_percentile": 0.55117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openNDS",
      "product": "openNDS",
      "cwe": "CWE-78",
      "title": "In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38822"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-18983",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onedesigns",
      "product": "One User Avatar | User Profile Picture",
      "cwe": "CWE-434",
      "title": "One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18983"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-40541",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0048,
      "epss_percentile": 0.39397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Chat Server",
      "cwe": "CWE-79",
      "title": "An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40541"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-6286",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.3685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "melograno",
      "product": "Booking for Appointments and Events Calendar – Amelia",
      "cwe": "CWE-79",
      "title": "Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6286"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-16759",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.35751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-74",
      "title": "Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16759"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-78032",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.34806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tsuyoshi Saito",
      "product": "SOY CMS",
      "cwe": "CWE-502",
      "title": "SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78032"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-5097",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-89",
      "title": "wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5097"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-9491",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.004,
      "epss_percentile": 0.32938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Chat Server",
      "cwe": "CWE-918",
      "title": "A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9491"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-14558",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.28511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Frontend",
      "cwe": "CWE-502",
      "title": "WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14558"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-76581",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.26472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "WPMU DEV Dashboard",
      "cwe": "CWE-347",
      "title": "WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76581"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-82089",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.2505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wallabag",
      "product": "android-app",
      "cwe": "CWE-79",
      "title": "The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82089"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-77365",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "optimole",
      "product": "Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization",
      "cwe": "CWE-79",
      "title": "Optimole <= 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77365"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-18324",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.22495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-79",
      "title": "Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18324"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-76053",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.22495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "TranslatePress – Translate Multilingual sites with AI Translation",
      "cwe": "CWE-79",
      "title": "TranslatePress <= 3.3.3 - Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76053"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-82090",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.20186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getpocket",
      "product": "Pocket",
      "cwe": "CWE-79",
      "title": "Pocket through 8.33.0.0 allows XSS because \"Save to Pocket\" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82090"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-18978",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litespeedtech",
      "product": "LiteSpeed Cache",
      "cwe": "CWE-79",
      "title": "LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18978"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-4246",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmet",
      "product": "ElementsKit Pro",
      "cwe": "CWE-79",
      "title": "ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4246"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-9548",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Chat Server",
      "cwe": "CWE-79",
      "title": "An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9548"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-15798",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextendweb",
      "product": "Smart Slider 3",
      "cwe": "CWE-79",
      "title": "Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15798"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-38821",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.09946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openNDS",
      "product": "openNDS",
      "cwe": "CWE-122",
      "title": "A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38821"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-3129",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litespeedtech",
      "product": "LiteSpeed Cache",
      "cwe": "CWE-79",
      "title": "LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3129"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-80617",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00183,
      "epss_percentile": 0.07931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: airoha: fix foe_check_time allocation size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80617"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-80671",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00183,
      "epss_percentile": 0.07932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf sched: Fix register_pid() overflow, strcpy, and BUG_ON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80671"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-80640",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00183,
      "epss_percentile": 0.07932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/fwctl: Fix __fortify_panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80640"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-80659",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.07635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: vub300: defer reset until cmd_mutex is unlocked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80659"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-80606",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/userptr: Hold notifier_lock for write on inject test path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80606"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-80665",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80665"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-80616",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.07427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80616"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-38819",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openNDS",
      "product": "openNDS",
      "cwe": "CWE-401",
      "title": "Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38819"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-80600",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.07234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: dat: acquire ARP hw source only after skb realloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80600"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-80630",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.07236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80630"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-80681",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.0723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: re-fetch eth header after route_shortcircuit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80681"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-80603",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.07238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80603"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-80670",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.07191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf tools: Use perf_env__get_cpu_topology() in machine__resolve()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80670"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-80601",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: gw: acquire ethernet header only after skb realloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80601"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-80604",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: core: Fix OOB read in hid_get_report for numbered reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80604"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-80590",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "inet: frags: strip GSO state from fragments before reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80590"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-80593",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (asus_atk0110) Check package count before accessing element",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80593"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-80599",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: dat: ensure accessible eth_hdr proto field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80599"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-80645",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80645"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-80591",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix listxattr handling of corrupted xattr entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80591"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-80619",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: fix potential UAF in aa_replace_profiles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80619"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-80622",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "char: tlclk: fix use-after-free in tlclk_cleanup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80622"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-80677",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80677"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-80680",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: amd-mp2: Unregister callback on adapter add failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80680"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-80646",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: guard against possible NULL deref in __in6_dev_stats_get()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80646"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-80664",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: xt_nat: reject unsupported target families",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80664"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82123",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tangible",
      "product": "Loops & Logic",
      "cwe": "CWE-79",
      "title": "WordPress Loops & Logic - Reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82123"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-80594",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80594"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-80595",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: ims-pcu - add response length checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80595"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-80597",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.0723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: maps: vmu-flash: fix NULL pointer dereference in initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80597"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-80605",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80605"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-80626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80626"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-80627",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "MIPS: mm: Fix out-of-bounds write in maar_res_walk()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80627"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-80644",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: don't BUG_ON an invalid journal dinode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80644"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-80647",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/hns: Fix warning in poll cq direct mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80647"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-80652",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ccp - Treat zero-length cert chain as query for blob lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80652"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-80679",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/dasd: Fix potential NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80679"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-80609",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00172,
      "epss_percentile": 0.06763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "qede: fix out-of-bounds check for cqe->len_list[]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80609"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-80684",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00172,
      "epss_percentile": 0.06766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: pci: Fix NULL dereference on AIBV allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80684"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-80635",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: wcn36xx: fix OOB read from short trigger BA firmware response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80635"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-80678",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: imx: Fix slave registration race and error handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80678"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-80598",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs3: fix out-of-bounds read in decompress_lznt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80598"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-80613",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "veth: fix NAPI leak in XDP enable error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80613"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-80649",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Fix OOB in scmi_power_name_get()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80649"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-80682",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv/mm: use physical alignment for vmemmap_start_pfn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80682"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-80663",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tools/power/x86/intel-speed-select: Harden daemon pidfile open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80663"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-80618",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80618"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-80620",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Revert \"PCI/MSI: Unmap MSI-X region on error\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80620"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-80660",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (occ) unregister sysfs devices outside occ lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80660"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-80669",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Disable xfrm_decode_session hook attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80669"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-80686",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80686"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-80615",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80615"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-80639",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00171,
      "epss_percentile": 0.06674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/test: Fix __fortify_panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80639"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-73827",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tsuyoshi Saito",
      "product": "SOY Calendar",
      "cwe": "CWE-79",
      "title": "SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73827"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-77838",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tsuyoshi Saito",
      "product": "SOY Calendar",
      "cwe": "CWE-79",
      "title": "SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77838"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-78238",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tsuyoshi Saito",
      "product": "SOY Gallery",
      "cwe": "CWE-79",
      "title": "SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78238"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-80694",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00168,
      "epss_percentile": 0.06265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80694"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-80596",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: ims-pcu - only expose sysfs attributes on control interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80596"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-80696",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (ltc4282) Fix reading the minimum alarm voltage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80696"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-80700",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vmwgfx: validate external BO copy bounds for both stride paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80700"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-80702",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80702"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-80637",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.0627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: synproxy: fix unaligned memory access in timestamp adjustment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80637"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-80691",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80691"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-80602",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/x86/amd/lbr: Fix kernel address leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80602"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-80611",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: processor_idle: Mark LPI enter functions as __cpuidle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80611"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-80624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mfd: cs42l43: Sanity check firmware size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80624"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-80629",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-af: npc: Fix size of entry2cntr_map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80629"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-80636",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: conntrack: revert ct extension genid infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80636"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-80650",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: atomisp: gc2235: fix UAF and memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80650"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-80654",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "soc: xilinx: Shutdown and free rx mailbox channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80654"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-80667",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5: LAG, MPESW, Fix missing complete() on devcom error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80667"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-80676",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Drivers: hv: vmbus: use generic driver_override infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80676"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-80689",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80689"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-80695",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (sht3x) Fix unaligned accesses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80695"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-80683",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: SCO: give the socket its own sco_conn reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80683"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-80653",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.0607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: hisi_sas: Add slave_destroy interface for v3 hw",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80653"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-80628",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: seq: oss: Serialize readq reset state with q->lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80628"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-80661",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ufs: core: tracing: Do not dereference pointers in TP_printk()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80661"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-80614",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: emac: Fix NULL pointer dereference in emac_probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80614"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-80662",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80662"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-80675",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libbpf: Reject non-exclusive metadata maps in the signed loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80675"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-80685",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/util: don't read __page_2 for order-1 folios in snapshot_page()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80685"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-12513",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Shared Files",
      "cwe": "CWE-73",
      "title": "Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12513"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-80592",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "samples/damon/mtier: fail early if address range parameters are invalid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80592"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-80607",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80607"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-80621",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80621"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-80623",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "coresight: ete: Always save state on power down",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80623"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-80643",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "EDAC/igen6: Fix call trace due to missing release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80643"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-80648",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: spacemit: fix NULL check in spacemit_pin_set_config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80648"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-80658",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.0607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80658"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-80666",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.0607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: sco: Fix a race condition in sco_sock_timeout()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80666"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-80687",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.0607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd/viommu: Release the igroup lock on the vdevice_size error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80687"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-80688",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv: drop __init from vec_check_unaligned_access_speed_all_cpus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80688"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-80701",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vmwgfx: enforce cursor size limits for MOB cursors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80701"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-80714",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00164,
      "epss_percentile": 0.0589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: do not propagate one-packet flag to synced conns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80714"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-80706",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.05888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "can: softing: fw_parse(): validate firmware record spans",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80706"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-80716",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.05889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: pcm: wake linked drain waiters on unlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80716"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-80718",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.05889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80718"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-80707",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.0589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80707"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-80717",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.05889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: validate Adaptation Indication parameter length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80717"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-80708",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00164,
      "epss_percentile": 0.05888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80708"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-80722",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: validate individual TWT params before driver setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80722"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-80709",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80709"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-80715",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00161,
      "epss_percentile": 0.05515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "igc: remove napi_synchronize() in igc_down()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80715"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-80704",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00159,
      "epss_percentile": 0.05383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: use proper context for logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80704"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-80723",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "of: reserved_mem: prevent OOB when too many dynamic regions are defined",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80723"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-80710",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/dasd: Fix undersized format-check buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80710"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-19084",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "shared-files-pro",
      "cwe": "CWE-73",
      "title": "Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19084"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-16654",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefusion",
      "product": "Avada (Fusion) Builder",
      "cwe": "CWE-79",
      "title": "Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16654"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-14567",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Frontend",
      "cwe": "CWE-200",
      "title": "WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14567"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-79706",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Breeze Cache",
      "cwe": "CWE-434",
      "title": "Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79706"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-80703",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80703"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-80711",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00156,
      "epss_percentile": 0.05091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: max17040: handle missing status supplier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80711"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-80612",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.0498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: lwtunnel: Drop skb metadata before LWT encapsulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80612"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-80634",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.0498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80634"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-80668",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.04974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_conntrack_expect: use conntrack GC to reap expectations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80668"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-80673",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.04976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80673"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-80674",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.04975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: validate resident attribute lists and harden the validator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80674"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-80693",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.04974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "idpf: bound interrupt-vector register fill to the allocated array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80693"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-80608",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: Fix iommu domain lifetime race during device removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80608"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-80633",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Take dma_resv lock before dma_buf_unpin() in release path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80633"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-80638",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80638"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-80672",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: fix u16 truncation of restart-area length check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80672"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-80692",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80692"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-80656",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hfsplus: Add a sanity check for btree node size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80656"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-80631",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: lzo: reject compressed segment that overflows the compressed input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80631"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-80610",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: enetc: fix potential divide-by-zero when num_vsi is zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80610"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-80625",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/hns: Fix memory leak of bonding resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80625"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-80632",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80632"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-80641",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: wlcore: enable the right set of ciphers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80641"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-80642",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "liveupdate: Reference count incoming FLB data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80642"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-80651",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80651"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-80655",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "soc: xilinx: Fix race condition in event registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80655"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-80657",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80657"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-80690",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: ufs: core: Initialize hba->rpmbs list in ufshcd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80690"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-80697",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: ensure valid f_path for page cache sharing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80697"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-80698",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.0498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: idxd: fix double free of wq, engine, and group structs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80698"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-80699",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00155,
      "epss_percentile": 0.04978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80699"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-80721",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.04897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: ISO: ensure no dangling hcon references in iso_conn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80721"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-80724",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.04897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ptp: vmclock: prevent read-only mappings from becoming writable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80724"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-80712",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.04896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: spi-qpic-snand: write the feature value before executing SET_FEATURE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80712"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-80720",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.04897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iomap: add a separate bio_set for iomap_split_ioend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80720"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-19423",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Member",
      "cwe": "CWE-269",
      "title": "Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19423"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-82081",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wallabag",
      "product": "wallabag",
      "cwe": "CWE-918",
      "title": "wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82081"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-12514",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Shared Files",
      "cwe": "CWE-862",
      "title": "Shared Files < 1.7.70 - Unauthenticated Limited File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12514"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-77701",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WCFM Marketplace",
      "cwe": "CWE-862",
      "title": "WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77701"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-80713",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring: preserve task restrictions across exec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80713"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-80705",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: check if dml21_add_phantom_plane() is successful",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80705"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-80719",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm: mglru: fix stale batch updates after memcg reparenting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80719"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-79996",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-269",
      "title": "User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79996"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-79995",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.0376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-639",
      "title": "User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79995"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-79615",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.0376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quiz and Survey Master (QSM)",
      "cwe": "CWE-639",
      "title": "Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79615"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-54745",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubeflow",
      "product": "pipelines",
      "cwe": "CWE-284",
      "title": "Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54745"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-82222",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "GiveWP",
      "cwe": "CWE-502",
      "title": "WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82222"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-18527",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Administration Runtime Expert for i",
      "cwe": "CWE-384",
      "title": "IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18527"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-19295",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-95",
      "title": "Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19295"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-55565",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-94",
      "title": "Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55565"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-55634",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-89",
      "title": "Pimcore: Remote Code Execution via DataObject Class-Definition Field Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55634"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-19286",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19286"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-37751",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37751"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-55559",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-94",
      "title": "Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55559"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-82329",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-287",
      "title": "Potential authentication bypass leading to administrative access in Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82329"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-54754",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-191",
      "title": "Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54754"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-54755",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-190",
      "title": "Klever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54755"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-82078",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut MF/NG",
      "cwe": "CWE-470",
      "title": "PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82078"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-82244",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-94",
      "title": "Budibase before 3.41.3 Remote Code Execution via Plugin eval()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82244"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-55068",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-20",
      "title": "free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55068"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-55220",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-502",
      "title": "Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55220"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-55378",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shriyanss",
      "product": "js-recon",
      "cwe": "CWE-78",
      "title": "JS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55378"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-82266",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "redpanda-data",
      "product": "redpanda",
      "cwe": "CWE-306",
      "title": "Redpanda Admin API Unauthenticated Superuser Access via Default Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82266"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-82277",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argoproj",
      "product": "argo-rollouts",
      "cwe": "CWE-306",
      "title": "Argo Rollouts Dashboard Unauthenticated Mutating Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82277"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-3627",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": null,
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3627"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-18918",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Lyo",
      "cwe": "CWE-863",
      "title": "OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18918"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-42007",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-416",
      "title": "An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42007"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-55247",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plone",
      "product": "plone.app.event",
      "cwe": "CWE-400",
      "title": "plone.app.event: Denial of service via iCalendar import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55247"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-55248",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plone",
      "product": "plone.app.portlets",
      "cwe": "CWE-400",
      "title": "plone.app.portlets: Denial of service via RSS feed portlet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55248"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-55511",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-94",
      "title": "Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55511"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-82281",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cinnamon",
      "product": "kotaemon",
      "cwe": "CWE-639",
      "title": "Kotaemon Missing Ownership Check in Conversation Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82281"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-82021",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-494",
      "title": "Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82021"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-13761",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pegasystems",
      "product": "Pega Infinity",
      "cwe": "CWE-606",
      "title": "Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13761"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-18729",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18729"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-55485",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "piccolo-orm",
      "product": "piccolo_admin",
      "cwe": "CWE-200",
      "title": "Piccolo Admin: Privilege escalation - admin to superuser via session-token disclosure in GET /api/tables/sessions/.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55485"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-55509",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mar10",
      "product": "wsgidav",
      "cwe": "CWE-89",
      "title": "WsgiDAV: Blind SQL injection in the MySQL provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55509"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-55521",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-862",
      "title": "Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55521"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-72984",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-843",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72984"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-81578",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut MF/NG",
      "cwe": "CWE-305",
      "title": "PaperCut MF/NG: Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81578"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-82282",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "runatlantis",
      "product": "atlantis",
      "cwe": "CWE-306",
      "title": "Atlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated Callers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82282"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-82285",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataelement",
      "product": "bisheng",
      "cwe": "CWE-918",
      "title": "BISHENG Unauthenticated Server-Side Request Forgery via Workflow Report Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82285"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-82286",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BuilderIO",
      "product": "gpt-crawler",
      "cwe": "CWE-22",
      "title": "gpt-crawler Arbitrary File Write via outputFileName Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82286"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-19412",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CP Plus",
      "product": "CP-XR-DE21-S Router",
      "cwe": "CWE-798",
      "title": "Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19412"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-55245",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maximhq",
      "product": "bifrost",
      "cwe": "CWE-918",
      "title": "Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55245"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-55763",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-841",
      "title": "Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55763"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-55764",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-190",
      "title": "Klever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55764"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-75118",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR100 v3.20",
      "cwe": "CWE-121",
      "title": "http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75118"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-75124",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-120",
      "title": "PLANET GS-4210-16P2S Memory Corruption via dispatcher.cgi _readHttpParam",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75124"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-78072",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jefferson49",
      "product": "Sexy Polling Reloaded extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78072"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-81517",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-248",
      "title": "MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81517"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-81518",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-295",
      "title": "BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81518"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-81520",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-1088",
      "title": "MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81520"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-81532",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-121",
      "title": "BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81532"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-81849",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amazon",
      "product": "amazon-ssm-agent",
      "cwe": "CWE-23",
      "title": "Path traversal in the aws:downloadContent plugin in amazon-ssm-agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81849"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-82247",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-522",
      "title": "gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82247"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-82251",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-22",
      "title": "gitoxide before 0.52.1 Path Traversal via Submodule Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82251"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-82252",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-59",
      "title": "gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82252"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-82253",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-22",
      "title": "gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82253"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-82254",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-248",
      "title": "gitoxide before 0.69.0 Denial of Service via gix-pack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82254"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-82259",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "kit",
      "cwe": "CWE-502",
      "title": "SvelteKit 2.49.0 before 2.53.3 Denial of Service via form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82259"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-82260",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "kit",
      "cwe": "CWE-400",
      "title": "SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82260"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-82261",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "kit",
      "cwe": "CWE-400",
      "title": "SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82261"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-82268",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QwenLM",
      "product": "Qwen-Agent",
      "cwe": "CWE-918",
      "title": "Qwen-Agent Server-Side Request Forgery via Caller-Supplied Document URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82268"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-82270",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Portkey-AI",
      "product": "gateway",
      "cwe": "CWE-918",
      "title": "Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82270"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-82275",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QwenLM",
      "product": "Qwen-Agent",
      "cwe": "CWE-22",
      "title": "Qwen-Agent Arbitrary File Read via Caller-Supplied Document Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82275"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-82278",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataelement",
      "product": "bisheng",
      "cwe": "CWE-94",
      "title": "BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82278"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-82288",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AUTOMATIC1111",
      "product": "stable-diffusion-webui",
      "cwe": "CWE-522",
      "title": "Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82288"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-55848",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mapfish",
      "product": "mapfish-print",
      "cwe": "CWE-611",
      "title": "mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55848"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-56100",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpringBlade",
      "product": "SpringBlade",
      "cwe": "CWE-862",
      "title": "SpringBlade 2.7.3 < 5.0.0 Privilege Escalation via Exposed Feign Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56100"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-75121",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-78",
      "title": "PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75121"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-75122",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-78",
      "title": "PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75122"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-75123",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-78",
      "title": "PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75123"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-82017",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IGEL",
      "product": "IGEL OS 12",
      "cwe": "CWE-345",
      "title": "IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82017"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-82239",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-862",
      "title": "Budibase before 3.41.3 Authorization Bypass via datasources/query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82239"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-82240",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-862",
      "title": "Budibase before 3.41.3 Privilege Escalation via User Update API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82240"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-82269",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gophish",
      "product": "gophish",
      "cwe": "CWE-288",
      "title": "Gophish Account Lockout and Forced Password Change Bypassable via API Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82269"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-82283",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VoltAgent",
      "product": "voltagent",
      "cwe": "CWE-639",
      "title": "VoltAgent Memory API Handlers Missing Ownership Checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82283"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-82284",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuivrHQ",
      "product": "quivr",
      "cwe": "CWE-639",
      "title": "Quivr Chat Endpoints Missing Ownership Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82284"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-82287",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rybbit-io",
      "product": "rybbit",
      "cwe": "CWE-942",
      "title": "Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82287"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-55108",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubevela",
      "product": "kubevela",
      "cwe": "CWE-59",
      "title": "KubeVela Terraform remote loader DoS via unbounded file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55108"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-75486",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "snyk",
      "product": "sweater-comb",
      "cwe": "CWE-78",
      "title": "Synk Sweater Comb < 3.8.8 Command Injection via .vervet.yaml Branch Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75486"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-77586",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-89",
      "title": "MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77586"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-82227",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "WPBulky",
      "cwe": "CWE-89",
      "title": "WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82227"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-82234",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-918",
      "title": "SiYuan before v3.8.1 SSRF via DNS-Rebinding TOCTOU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82234"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-81490",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-476",
      "title": "MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of SQL Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81490"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-82242",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-862",
      "title": "Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82242"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-82243",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-918",
      "title": "Budibase Server before 3.41.3 SSRF with Credential Leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82243"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-82289",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coderamp-labs",
      "product": "gitingest",
      "cwe": "CWE-918",
      "title": "Gitingest Prefix-Based Git Host Check Enables Request Forgery and Token Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82289"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-18891",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-287",
      "title": "Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18891"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-18904",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18904"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-82235",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-400",
      "title": "filebrowser through 2.63.23 Denial of Service via named pipes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82235"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-82262",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-918",
      "title": "Logto Server-Side Request Forgery via webhook test endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82262"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-82263",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-918",
      "title": "Logto Server-Side Request Forgery via OIDC SSO Connector Issuer URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82263"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-50979",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50979"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-55065",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-285",
      "title": "Vikunja: Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55065"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-82291",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heyform",
      "product": "heyform",
      "cwe": "CWE-942",
      "title": "HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82291"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-82020",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-552",
      "title": "Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82020"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-82255",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-522",
      "title": "gitoxide 0.25.4 HTTP Credential Leak via Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82255"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-17203",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Administration Runtime Expert for i",
      "cwe": "CWE-287",
      "title": "IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17203"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-18899",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18899"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-27852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27852"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-33605",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33605"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-37237",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp and call r.read() without enforcing a maximum response size, allowing an attacker to exhaust server memory by providing a URL to an arbitrarily large file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37237"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-37736",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-770",
      "title": "An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37736"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-38636",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38636"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-38638",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38638"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-42391",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42391"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-54788",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-rs",
      "cwe": "CWE-770",
      "title": "dd-trace-rs: Unbounded W3C tracestate parsing may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54788"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-55215",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-nodejs",
      "cwe": "CWE-295",
      "title": "MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: true`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55215"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-55484",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guno1928",
      "product": "alos-http",
      "cwe": "CWE-248",
      "title": "ALOS HTTP: Unauthenticated remote DoS: malformed path starting with \"?\" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55484"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-55552",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-22",
      "title": "Yamcs: Unauthenticated Directory Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55552"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-55584",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpsysinfo",
      "product": "phpsysinfo",
      "cwe": "CWE-290",
      "title": "phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55584"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-55784",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-362",
      "title": "free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55784"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-55841",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Graylog2",
      "product": "graylog2-server",
      "cwe": "CWE-138",
      "title": "Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55841"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-56854",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-863",
      "title": "Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56854"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-77037",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multer",
      "product": "multer",
      "cwe": "CWE-400",
      "title": "multer vulnerable to Denial of Service via file descriptor leak on aborted uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77037"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-77078",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multer",
      "product": "multer",
      "cwe": "CWE-248",
      "title": "multer vulnerable to Denial of Service via crafted multipart field names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77078"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-78071",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digital-peak.com",
      "product": "DP Calendar extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78071"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-81285",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Smush Image Compression and Optimization",
      "cwe": "CWE-770",
      "title": "WordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81285"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-81767",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yalla ya!",
      "product": "Simple Payment",
      "cwe": "CWE-862",
      "title": "WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81767"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-82333",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multer",
      "product": "multer",
      "cwe": "CWE-400",
      "title": "multer vulnerable to Denial of Service via oversized array index in field names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82333"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-40018",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-89",
      "title": "None None None No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40018"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-73208",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-287",
      "title": "An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with Dovecot, and that configured scope names do not match audience values. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73208"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-81019",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL Inc.",
      "product": "wolfProvider",
      "cwe": "CWE-323",
      "title": "wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81019"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-81020",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL Inc.",
      "product": "wolfEngine",
      "cwe": "CWE-323",
      "title": "wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81020"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-5934",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Media",
      "product": "WP Rocket",
      "cwe": "CWE-79",
      "title": "WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5934"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-6176",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivole",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-79",
      "title": "Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6176"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-81757",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rank Math SEO",
      "product": "Rank Math SEO",
      "cwe": "CWE-502",
      "title": "WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81757"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-82245",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-862",
      "title": "Budibase before 3.41.3 Missing Authorization License Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82245"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-82279",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hyperdxio",
      "product": "hyperdx",
      "cwe": "CWE-862",
      "title": "HyperDX Team Management Operations Missing Role-Based Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82279"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-55066",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-639",
      "title": "Vikunja: Cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55066"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-55520",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scrapy",
      "product": "protego",
      "cwe": "CWE-400",
      "title": "Protego: Exponential backtracking ReDoS in robots.txt URL wildcard matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55520"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-55673",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "powsybl",
      "product": "powsybl-core",
      "cwe": "CWE-78",
      "title": "PowSyBl: Command Injection in LocalCommandExecutor-s",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55673"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-77939",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flextype",
      "product": "flextype",
      "cwe": "CWE-94",
      "title": "Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77939"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-81760",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.14.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81760"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-82241",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-918",
      "title": "Budibase backend-core SSRF via incomplete default blacklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82241"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-82246",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "budibase",
      "product": "server",
      "cwe": "CWE-918",
      "title": "Budibase Server before 3.41.3 SSRF via Query Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82246"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-82250",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-191",
      "title": "gitoxide gix-packetline before 0.21.5 Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82250"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-82271",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SciPhi-AI",
      "product": "R2R",
      "cwe": "CWE-639",
      "title": "R2R Missing Ownership Check Allows Modifying Other Users' Conversations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82271"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-82272",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "immich-app",
      "product": "immich",
      "cwe": "CWE-863",
      "title": "Immich Locked Assets Remain Readable Through Albums and Shared Links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82272"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-82273",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastra-ai",
      "product": "mastra",
      "cwe": "CWE-862",
      "title": "Mastra Memory API Thread Ownership Check Is a No-op When mapUserToResourceId Is Unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82273"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-82280",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuivrHQ",
      "product": "quivr",
      "cwe": "CWE-639",
      "title": "Quivr Prompt Endpoints Missing Ownership Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82280"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-16821",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "AIX",
      "cwe": "CWE-134",
      "title": "Vulnerabilities in IBM AIX and PowerVM VIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16821"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-55678",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Basekick-Labs",
      "product": "arc",
      "cwe": "CWE-284",
      "title": "Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55678"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-75125",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-476",
      "title": "PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_post",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75125"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-75126",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-121",
      "title": "PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Standard Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75126"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-76798",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector Transition Readiness Report",
      "cwe": "CWE-79",
      "title": "MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML Reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76798"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-77217",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-121",
      "title": "PLANET GS-4210-16P2S Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi RADIUS Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77217"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-77218",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET GS-4210-16P2S",
      "cwe": "CWE-121",
      "title": "PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Credential Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77218"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-78070",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digital-peak.com",
      "product": "DP Calendar extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78070"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-81732",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo through 30.0 Information Disclosure via report4.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81732"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-82233",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan before v3.8.1 Path Traversal via asset.upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82233"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-82256",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "kit",
      "cwe": "CWE-400",
      "title": "SvelteKit before 2.69.1 Denial of Service via Remote Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82256"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-82265",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openzipkin",
      "product": "zipkin",
      "cwe": "CWE-306",
      "title": "Zipkin Unauthenticated Spring Boot Actuator Endpoints Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82265"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-82018",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IGEL",
      "product": "IGEL OS 12",
      "cwe": "CWE-636",
      "title": "IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82018"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-82181",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Le-yan",
      "product": "Medical Practice Management System",
      "cwe": "CWE-598",
      "title": "Le-yan｜Medical Practice Management System - Sensitive Data in URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82181"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-55569",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aquaproj",
      "product": "aqua",
      "cwe": "CWE-22",
      "title": "aqua: Archive extraction in aqua follows attacker-planted symlinks, allowing writes outside the install directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55569"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-13734",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-294",
      "title": "Zephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay endpoint hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13734"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-40014",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40014"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-40017",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40017"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-52687",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52687"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-55545",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-862",
      "title": "Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enforce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55545"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-55549",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-79",
      "title": "Yamcs: Reflected XSS in the URL of the Authorize Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55549"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-55855",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-nodejs",
      "cwe": "CWE-89",
      "title": "MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55855"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-66324",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-73",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66324"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-73209",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-674",
      "title": "An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73209"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-81341",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL Inc.",
      "product": "wolfEngine",
      "cwe": "CWE-323",
      "title": "wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81341"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-82306",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StarRocks",
      "product": "starrocks",
      "cwe": "CWE-200",
      "title": "StarRocks Query Detail Endpoint Returns Every User's Query History",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82306"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-3423",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More",
      "cwe": "CWE-79",
      "title": "Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3423"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-5510",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "GiveWP – Donation Plugin and Fundraising Platform",
      "cwe": "CWE-79",
      "title": "GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5510"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-6128",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "servmask",
      "product": "All-in-One WP Migration Unlimited Extension",
      "cwe": "CWE-79",
      "title": "All-in-One WP Migration Unlimited Extension <= 2.84 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ai1wm_backups_path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6128"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-19294",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19294"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-54746",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hatchet-dev",
      "product": "hatchet",
      "cwe": "CWE-639",
      "title": "Hatchet: Cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54746"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-3686",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Data System",
      "cwe": "CWE-770",
      "title": "Vulnerabilities exists in IBM Cloud Pak for Data System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3686"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-5800",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dayneks Software Industry and Trade Inc.",
      "product": "E-Commerce Platform",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Dayneks Software's E-Commerce Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5800"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-5953",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ceviz Informatics Inc.",
      "product": "Web Design",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Ceviz Informatics's Web Design",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5953"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-37710",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37710"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-82264",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gilbertchen",
      "product": "duplicacy",
      "cwe": "CWE-22",
      "title": "Duplicacy Path Traversal during Restore via Unsanitized Snapshot Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82264"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-82324",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-125",
      "title": "Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82324"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-82328",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-125",
      "title": "Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82328"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-82330",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-125",
      "title": "Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82330"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-82343",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-120",
      "title": "Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82343"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-81533",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-121",
      "title": "MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81533"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-82248",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-59",
      "title": "gitoxide before 0.33.0 Path Traversal via symlink following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82248"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-82290",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chainlit",
      "product": "chainlit",
      "cwe": "CWE-639",
      "title": "Chainlit Feedback Endpoints Missing Ownership Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82290"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2025-36271",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Integrated Analytics System",
      "cwe": "CWE-759",
      "title": "IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36271"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2025-36290",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Integrated Analytics System",
      "cwe": "CWE-295",
      "title": "IBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certificate validation vulnerability in JWT service component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36290"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2025-64649",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-295",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64649"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-33604",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-655",
      "title": "An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message content from being interpreted as SMTP commands. A downstream mail server that hasn't yet fixed the SMTP smuggling vulnerability can be tricked into treating part of the message body as new SMTP commands, allowing injection of spoofed email. This is the same vulnerability class as CVE-2023-51764 and CVE-2023-51766. Where you control the receiving mail servers, ensure they reject bare carriage returns in message data. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33604"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-40019",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot CE",
      "cwe": "CWE-400",
      "title": "An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40019"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-40205",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-287",
      "title": "An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requires all of them. The configured authorization policy is not enforced, so a token that was granted only part of the required permissions is accepted where it should have been rejected. Use local token validation where tokens can be validated locally. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40205"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-55854",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-nodejs",
      "cwe": "CWE-319",
      "title": "MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55854"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-55856",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-j",
      "cwe": "CWE-522",
      "title": "MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55856"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-55857",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-j",
      "cwe": "CWE-319",
      "title": "MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55857"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-55858",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-j",
      "cwe": "CWE-838",
      "title": "MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariadb-java-client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55858"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-55859",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-r2dbc",
      "cwe": "CWE-116",
      "title": "MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output in org.mariadb:r2dbc-mariadb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55859"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-55860",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-r2dbc",
      "cwe": "CWE-319",
      "title": "MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55860"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-75758",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-lang",
      "product": "elixir",
      "cwe": "CWE-674",
      "title": "Unbounded recursion between Inspect.List charlist rendering and List.to_string/1 error path in Elixir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75758"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-82258",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "kit",
      "cwe": "CWE-362",
      "title": "SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82258"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-76797",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector Transition Readiness Report",
      "cwe": "CWE-1236",
      "title": "MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated Reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76797"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-77184",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector",
      "cwe": "CWE-89",
      "title": "MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77184"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-58107",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "CodeChecker",
      "cwe": "CWE-409",
      "title": "Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58107"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-82327",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-129",
      "title": "Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82327"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-4378",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akilli Ticaret Software Technologies Ltd.",
      "product": "E-Commerce Pack",
      "cwe": "CWE-79",
      "title": "Stored XSS in Akıllı Ticaret's E-Commerce Pack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4378"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-18393",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
      "cwe": "CWE-787",
      "title": "Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18393"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-38725",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates without output escaping, resulting in Stored Cross-Site Scripting (XSS). When an administrator reviews comments in the back office, the payload executes with admin-level session context, leading to full store compromise.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38725"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-55779",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silverstripe",
      "product": "silverstripe-versioned",
      "cwe": "CWE-79",
      "title": "Silverstripe Versioned: XSS in archive admin restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55779"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-62904",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-863",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62904"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-66323",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-141",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66323"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-70309",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70309"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-70331",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-1427",
      "title": "Microsoft Edge for iOS Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70331"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-81759",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpEvently",
      "cwe": "CWE-862",
      "title": "WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81759"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-5096",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI",
      "cwe": "CWE-918",
      "title": "Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5096"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-15603",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "morgan",
      "product": "morgan",
      "cwe": "CWE-117",
      "title": "morgan vulnerable to Log Forging via unescaped Unicode line separators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15603"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-54766",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-285",
      "title": "Vikunja: Project duplication bypasses write-permission check on the target parent project",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54766"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-55867",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Graylog2",
      "product": "graylog2-server",
      "cwe": "CWE-639",
      "title": "Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55867"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-76649",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link System Inc.",
      "product": "TL-WR841N v14",
      "cwe": "CWE-476",
      "title": "Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-Link TL-WR841N",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76649"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-76650",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link System Inc.",
      "product": "TL-WR841N v14",
      "cwe": "CWE-476",
      "title": "Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing in TP-Link TL-WR841N",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76650"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-76651",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link System Inc.",
      "product": "TL-WR841N v14",
      "cwe": "CWE-120",
      "title": "Pre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-Link TL-WR841N",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76651"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-78073",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mrvinoth.com",
      "product": "All Video Share extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - j2commerce.com - Reflected XSS attribute in All Video Share 1.0.0-4.5.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78073"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-81777",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "Essential Addons for Elementor",
      "cwe": "CWE-290",
      "title": "WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81777"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-82220",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Forminator",
      "cwe": "CWE-294",
      "title": "WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82220"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-82257",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "kit",
      "cwe": "CWE-1321",
      "title": "SvelteKit before 2.69.1 Prototype Pollution via File Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82257"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-82267",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moghtech",
      "product": "komodo",
      "cwe": "CWE-862",
      "title": "Komodo Resource Identifier Disclosure and Audit Log Pollution Before Permission Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82267"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-82274",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-601",
      "title": "Twenty Open Redirect via OAuth Propagator Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82274"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-82276",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StarRocks",
      "product": "starrocks",
      "cwe": "CWE-306",
      "title": "StarRocks Frontend REST Handlers Bypass the Base Class Authentication Gate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82276"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-81733",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo through 30.0 CSRF via myLiveControls.save.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81733"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-82112",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "houtini-ai",
      "product": "houtini-lm",
      "cwe": "CWE-22",
      "title": "houtini-ai houtini-lm code_task_files index.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82112"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-55067",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-639",
      "title": "Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55067"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-55425",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Graylog2",
      "product": "graylog2-server",
      "cwe": "CWE-213",
      "title": "Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55425"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-33606",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-93",
      "title": "Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33606"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-76794",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "BI Connector Transition Readiness Report",
      "cwe": "CWE-79",
      "title": "MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Database Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76794"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-58616",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-362",
      "title": "Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58616"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-18545",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18545"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-33263",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-403",
      "title": "When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the new submission connection gets terminated. If running in high-performance mode (default for Pro releases), all connections handled by the submission-login process will be terminated. The crashes can cause failure for user to send a message, or it can cause duplicate messages to be sent. If TLS is not used (in the backend server processing the submission), duplicate deliveries cannot happen, because the crash can only happen at AUTH stage. Limit the number of connections handled by single submission-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33263"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-33607",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33607"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-40013",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-124",
      "title": "An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40013"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-40015",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-125",
      "title": "An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40015"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-42008",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-287",
      "title": "Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any host permitted to act as a trusted proxy can authenticate as any user without knowing that user's password. This affects deployments whose password database honours a field that permits authentication without a password. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42008"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-42392",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-200",
      "title": "An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42392"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-42395",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-400",
      "title": "A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42395"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-55064",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-862",
      "title": "Vikunja incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55064"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-55547",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-285",
      "title": "Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55547"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-55566",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-79",
      "title": "Yamcs: DOM XSS in Extension Routing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55566"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-55696",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrivateBin",
      "product": "PrivateBin",
      "cwe": "CWE-79",
      "title": "PrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55696"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-55834",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pocket-id",
      "product": "pocket-id",
      "cwe": "CWE-601",
      "title": "Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55834"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-66798",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-416",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66798"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-81284",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ACF Extended",
      "product": "ACF Extended",
      "cwe": "CWE-862",
      "title": "WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81284"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-81299",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "WP Job Portal",
      "cwe": "CWE-639",
      "title": "WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81299"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-81761",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpEvently",
      "cwe": "CWE-862",
      "title": "WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81761"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-13735",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-290",
      "title": "WireGuard keepalive transport-data messages accepted without Poly1305 authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13735"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-40203",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-200",
      "title": "When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40203"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-55785",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-208",
      "title": "free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55785"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-77063",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multer",
      "product": "multer",
      "cwe": "CWE-362",
      "title": "multer vulnerable to file size limit bypass via async fileFilter race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77063"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-38093",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses the DISPLAY_NAME obtained from ContentResolver.query() directly in file path construction without sanitization. A malicious Android app with a crafted ContentProvider can return a filename containing ../ sequences, causing the plugin to create arbitrary files and directories outside the intended cache directory within the victim app's internal storage. Existing files are not overwritten due to an existence check.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38093"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-40204",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-284",
      "title": "None None None No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40204"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-42393",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-200",
      "title": "The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42393"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-52681",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open-Xchange GmbH",
      "product": "OX Dovecot Pro",
      "cwe": "CWE-1050",
      "title": "Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52681"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-22056",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetApp",
      "product": "StorageGRID",
      "cwe": "CWE-774",
      "title": "CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22056"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-82236",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-459",
      "title": "File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82236"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-82237",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-459",
      "title": "filebrowser through 2.63.23 Stale Share Link via File Rename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82237"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-82238",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-367",
      "title": "filebrowser 2.24.0 Race Condition via TUS concurrent PATCH uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82238"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-82249",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-116",
      "title": "gitoxide before 0.38.2 Credential Helper Protocol Field Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82249"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-82111",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iswalle",
      "product": "getnote-mcp",
      "cwe": "CWE-22",
      "title": "iswalle getnote-mcp upload_image index.ts fs.readFileSync path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82111"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-58106",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "CodeChecker",
      "cwe": "CWE-787",
      "title": "Incomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into fullPath+2, writing 2 bytes past the buffer on every CodeChecker log invocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58106"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-55891",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrivateBin",
      "product": "PrivateBin",
      "cwe": "CWE-116",
      "title": "PrivateBin: Reflected JSON injection in backend responses via unescaped REQUEST_URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55891"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-37236",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37236"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-39070",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect user to malicious site or control the account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39070"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-39071",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39071"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-50980",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50980"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-51376",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51376"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-51610",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51610"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-51611",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51611"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-51613",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51613"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-51614",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51614"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-51615",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51615"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-51616",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51616"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-51617",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected client statistics via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51617"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-51618",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51618"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-51619",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51619"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-51620",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51620"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-51621",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51621"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-51622",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51622"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-51623",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51623"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-51624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51624"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-51625",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51625"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-51626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51626"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-51627",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51627"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-51628",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51628"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-51629",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51629"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-51630",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51630"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-51631",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51631"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-51632",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51632"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-51633",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51633"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-51634",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51634"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-51635",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51635"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-51636",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51636"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-51637",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh portal table information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51637"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-51638",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain guest Wi-Fi configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51638"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-51639",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain AP-specific Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51639"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-51640",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh neighbor information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51640"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-51641",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51641"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-51642",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51642"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-51643",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51643"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-51644",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51644"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-51645",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51645"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-51646",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51646"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-51647",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51647"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-51648",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51648"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-51649",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51649"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-51650",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51650"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-51651",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51651"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-51652",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51652"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-51653",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51653"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-51654",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51654"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-51655",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51655"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-51656",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain VPN pass-through and WAN ping filter settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51656"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-51657",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51657"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-51658",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51658"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-51659",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51659"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-51660",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51660"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-51661",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51661"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-51662",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51662"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-51663",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51663"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-51664",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51664"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-51665",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51665"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-43900",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-43900. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-43901",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-43901. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-43902",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-43902. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-2609",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-2609 (MagnusSolution MagnusBilling). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-2610",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-2610 (MagnusSolution MagnusBilling). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-43955",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-43955 (Convertigo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0545",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0545 (mlflow/mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10036",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19092",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19092 (Unknown Tutor LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2614",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2614 (mlflow/mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35397",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35397 (jupyter-server jupyter_server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-38636",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-38636. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-38638",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-38638. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42264 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44486 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44487 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44488 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44494 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44513",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44513 (huggingface diffusers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45736",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47117",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47117 (maziyarpanahi openmed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5241 (huggingface/transformers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75417",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75417. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76640",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76640 (Unitree Robotics G1 EDU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76886",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76886 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76888",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76888 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79804",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79804 (SililaWijesinghe Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81203",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81203 (SourceCodester Simple Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81560",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81560 (blackms aistack). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81834",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81834 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81934",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81934 (Redis). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-9147",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-9147 (scikit-hep uproot). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-21962",
      "detail": "DUE DATE PASSED — CVE-2026-21962 (Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in). CISA remediation deadline was August 27, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-43901",
      "detail": "RESCORED — CVE-2023-43901. CVSS 5.4 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-43902",
      "detail": "RESCORED — CVE-2023-43902. CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-58377",
      "detail": "RESCORED — CVE-2024-58377 (sparklemotion nokogiri). CVSS 9.3 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-2609",
      "detail": "RESCORED — CVE-2025-2609 (MagnusSolution MagnusBilling). CVSS 8.2 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-2610",
      "detail": "RESCORED — CVE-2025-2610 (MagnusSolution MagnusBilling). CVSS 7.6 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-43955",
      "detail": "RESCORED — CVE-2025-43955 (Convertigo). CVSS 2.2 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0545",
      "detail": "RESCORED — CVE-2026-0545 (mlflow/mlflow). CVSS 9.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16782",
      "detail": "RESCORED — CVE-2026-16782 (Autodesk 3ds Max). CVSS 5.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50768",
      "detail": "RESCORED — CVE-2026-50768. CVSS 9.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-67275",
      "detail": "RESCORED — CVE-2026-67275 (Dell PowerProtect One). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73571",
      "detail": "RESCORED — CVE-2026-73571 (Zimbra Collaboration). CVSS 3.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73573",
      "detail": "RESCORED — CVE-2026-73573 (Zimbra Collaboration). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73574",
      "detail": "RESCORED — CVE-2026-73574 (Zimbra Collaboration). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73575",
      "detail": "RESCORED — CVE-2026-73575 (Zimbra Collaboration). CVSS 3.1 → 3.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73576",
      "detail": "RESCORED — CVE-2026-73576 (Zimbra Collaboration). CVSS 6.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73626",
      "detail": "RESCORED — CVE-2026-73626 (jupyterlab). CVSS 0 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74774",
      "detail": "RESCORED — CVE-2026-74774 (Dell PowerProtect One). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74802",
      "detail": "RESCORED — CVE-2026-74802 (siyuan-note siyuan). CVSS 0 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-74887",
      "detail": "RESCORED — CVE-2026-74887 (jahlives openssl_encrypt). CVSS 9.3 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76886",
      "detail": "RESCORED — CVE-2026-76886 (Wireshark Foundation Wireshark). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76888",
      "detail": "RESCORED — CVE-2026-76888 (Wireshark Foundation Wireshark). CVSS 3.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80200",
      "detail": "RESCORED — CVE-2026-80200 (kimai). CVSS 0 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81835",
      "detail": "RESCORED — CVE-2026-81835 (RooCodeInc Roo-Code). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81836",
      "detail": "RESCORED — CVE-2026-81836 (RooCodeInc Roo-Code). CVSS 6.3 → 2.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81837",
      "detail": "RESCORED — CVE-2026-81837 (RooCodeInc Roo-Code). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81845",
      "detail": "RESCORED — CVE-2026-81845 (arben-adm mcp-sequential-thinking). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81847",
      "detail": "RESCORED — CVE-2026-81847 (MAA-AI MaaMCP). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2023-36664",
      "detail": "ENRICHED — CVE-2023-36664. Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-78195",
      "detail": "ENRICHED — CVE-2026-78195. Received CVSS 5.1 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
