{
  "day": "2026-08-30",
  "boundary": "UTC calendar day",
  "published_count": 92,
  "by_severity": {
    "CRITICAL": 6,
    "HIGH": 19,
    "MEDIUM": 32,
    "LOW": 28
  },
  "kev_count": 0,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 7,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-15980",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TangibleWP",
      "product": "MyHome Core",
      "cwe": "CWE-289",
      "title": "MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15980"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-82478",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.25625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "Trick",
      "cwe": "CWE-119",
      "title": "NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82478"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-82479",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "cFS",
      "cwe": "CWE-119",
      "title": "NASA cFS SBN TCP sbn_tcp_if.c OS_read buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82479"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-82480",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.12892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "cFS",
      "cwe": "CWE-189",
      "title": "NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82480"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-82484",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System emp_searchfrm.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82484"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-82485",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System pro_edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82485"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-82482",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.09671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coppermine-gallery",
      "product": "Coppermine Photo Gallery",
      "cwe": "CWE-79",
      "title": "coppermine-gallery Coppermine Photo Gallery edit_profile Endpoint profile.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82482"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-82483",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.09671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coppermine-gallery",
      "product": "Coppermine Photo Gallery",
      "cwe": "CWE-79",
      "title": "coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82483"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-14307",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "geotargetingwp",
      "cwe": null,
      "title": "Geotargeting WP < 3.5.6.2 - Reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14307"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-19722",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.0672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPvivid — Backup, Migration & Staging",
      "cwe": null,
      "title": "WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19722"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-76585",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.0677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Customer Reviews for WooCommerce",
      "cwe": null,
      "title": "Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76585"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-81660",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Groundhogg — CRM, Newsletters, and Marketing Automation",
      "cwe": null,
      "title": "Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81660"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-14835",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00153,
      "epss_percentile": 0.04747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SOGO Add Script to Individual Pages Header Footer",
      "cwe": null,
      "title": "SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post Metabox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14835"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-78364",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00152,
      "epss_percentile": 0.04705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MW WP Form",
      "cwe": null,
      "title": "MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78364"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-81766",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00147,
      "epss_percentile": 0.04266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Really Simple Security",
      "cwe": null,
      "title": "Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81766"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-77846",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00139,
      "epss_percentile": 0.03538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_sqlite",
      "cwe": "CWE-943",
      "title": "JSON path injection via unescaped get_path segments in AshSqlite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77846"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-77831",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_paper_trail",
      "cwe": "CWE-407",
      "title": "Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77831"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-75759",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "erlef",
      "product": "oidcc",
      "cwe": "CWE-347",
      "title": "Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75759"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-75847",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_paper_trail",
      "cwe": "CWE-312",
      "title": "Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75847"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-77970",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_paper_trail",
      "cwe": "CWE-312",
      "title": "Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77970"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-82593",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-825M",
      "cwe": "CWE-121",
      "title": "D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82593"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-82542",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG10",
      "cwe": "CWE-119",
      "title": "Tenda HG10 Boa Web Server formIPv6Routing buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82542"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-82653",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.8.1 Stored XSS via confirmDialog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82653"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-82654",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.8.1 Stored XSS via block name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82654"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-82645",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-347",
      "title": "AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82645"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-82635",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tw93",
      "product": "Pake",
      "cwe": "CWE-22",
      "title": "Pake arbitrary file write via unsanitized download_file filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82635"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-82641",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keploy",
      "product": "keploy",
      "cwe": "CWE-306",
      "title": "keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82641"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-82642",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "readest",
      "product": "readest",
      "cwe": "CWE-79",
      "title": "Readest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead to arbitrary code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82642"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-56718",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AJCloud",
      "product": "AJY IPC Firmware",
      "cwe": "CWE-22",
      "title": "AJCloud AJY IPC Firmware Path Traversal via jdbhttpd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56718"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-81636",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_graphql",
      "cwe": "CWE-770",
      "title": "Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81636"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-82638",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jina-ai",
      "product": "reader",
      "cwe": "CWE-918",
      "title": "jina-ai reader Server-Side Request Forgery via disabled private-address guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82638"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-82639",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChatGPTNextWeb",
      "product": "NextChat",
      "cwe": "CWE-20",
      "title": "NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82639"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-82644",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-307",
      "title": "WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82644"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-82655",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-89",
      "title": "Admidio before 5.0.12 SQL Injection via relation_type_list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82655"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-82657",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-200",
      "title": "Admidio before 5.0.12 Authentication Bypass via RSS feeds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82657"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-82592",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-825M",
      "cwe": "CWE-119",
      "title": "D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82592"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-82539",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A720R",
      "cwe": "CWE-119",
      "title": "TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82539"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-82636",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qubes OS",
      "product": "Qubes OS",
      "cwe": "CWE-78",
      "title": "Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the \"system\" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82636"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-78699",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_postgres",
      "cwe": "CWE-252",
      "title": "rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78699"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-80223",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_graphql",
      "cwe": "CWE-863",
      "title": "Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80223"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-82634",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-863",
      "title": "Frappe Framework Development Branch Incorrect Authorization via Jinja Template Preview Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82634"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-82648",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-20",
      "title": "WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82648"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-82649",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-427",
      "title": "SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82649"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-78693",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_graphql",
      "cwe": "CWE-209",
      "title": "Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78693"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-81633",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_graphql",
      "cwe": "CWE-20",
      "title": "Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81633"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-82637",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browser-use",
      "product": "web-ui",
      "cwe": "CWE-73",
      "title": "browser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82637"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-82643",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-307",
      "title": "WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82643"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-82651",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-200",
      "title": "SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82651"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-82652",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-668",
      "title": "SiYuan before v3.8.1 Information Disclosure via Publish Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82652"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82640",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browser-use",
      "product": "web-ui",
      "cwe": "CWE-312",
      "title": "browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82640"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-77454",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_sql",
      "cwe": "CWE-863",
      "title": "exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77454"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-78038",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_oban",
      "cwe": "CWE-915",
      "title": "Job argument injection via :args overrides primary_key and tenant in AshOban",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78038"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-78228",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_oban",
      "cwe": "CWE-674",
      "title": "Unbounded handle_error recursion enables denial of service in AshOban triggers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78228"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-81319",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_cloak",
      "cwe": "CWE-502",
      "title": "Unsafe deserialization of decrypted terms enables node DoS in AshCloak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81319"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-82650",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-668",
      "title": "SiYuan before v3.8.1 Path Traversal via /api/template/render",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82650"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-82543",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vastsa",
      "product": "FileCodeBox",
      "cwe": "CWE-362",
      "title": "vastsa FileCodeBox Pickup Limit views.py update_file_usage race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82543"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-82547",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Foundation",
      "product": "Magma",
      "cwe": "CWE-287",
      "title": "Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82547"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-82548",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Foundation",
      "product": "Magma",
      "cwe": "CWE-200",
      "title": "Linux Foundation Magma InitialUEMessage information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82548"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-82549",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Foundation",
      "product": "Magma",
      "cwe": "CWE-345",
      "title": "Linux Foundation Magma SecurityModeComplete integrity check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82549"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-82550",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Foundation",
      "product": "Magma",
      "cwe": "CWE-20",
      "title": "Linux Foundation Magma NGSetupRequest input validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82550"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-82551",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Foundation",
      "product": "Magma",
      "cwe": "CWE-371",
      "title": "Linux Foundation Magma NGSetup ngap_amf_handlers.c state issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82551"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-82544",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-352",
      "title": "wger-project wger Password Reset gym.py reset_user_password cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82544"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-82588",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-404",
      "title": "Open5GS Transfer Endpoint namf-handler.c null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82588"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-82590",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-617",
      "title": "Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82590"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-82595",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-825M",
      "cwe": "CWE-77",
      "title": "D-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82595"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-82633",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-862",
      "title": "Dolibarr 10.0.0 before 24.0.0 Missing Authorization on REST Users Groups Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82633"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-82646",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82646"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-82647",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82647"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-82658",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-285",
      "title": "Admidio before 5.0.12 Broken Access Control via profile_function.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82658"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-82591",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Asset Import Library",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Open Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82591"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-82555",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "N600R",
      "cwe": "CWE-310",
      "title": "TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82555"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-81643",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_graphql",
      "cwe": "CWE-863",
      "title": "Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81643"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-82367",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_graphql",
      "cwe": "CWE-488",
      "title": "Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82367"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-82486",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SiteServer",
      "product": "SSCMS",
      "cwe": "CWE-266",
      "title": "SiteServer SSCMS Agent Installation Workflow access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82486"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-82594",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LogNet",
      "product": "grpc-spring-boot-starter",
      "cwe": "CWE-285",
      "title": "LogNet grpc-spring-boot-starter Annotation Processing improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82594"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-78691",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_sql",
      "cwe": "CWE-943",
      "title": "Unescaped backslash allows LIKE wildcard injection in AshSql string search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78691"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-80227",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_sql",
      "cwe": "CWE-697",
      "title": "SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80227"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-81316",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_sql",
      "cwe": "CWE-863",
      "title": "Same-named aggregates with differing filters are conflated in AshSql",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81316"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-81318",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_sql",
      "cwe": "CWE-863",
      "title": "Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81318"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-81322",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_cloak",
      "cwe": "CWE-200",
      "title": "Cloaked plaintext leaks through a non-sensitive action argument in AshCloak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81322"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-82487",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Beetel",
      "product": "450TC3",
      "cwe": "CWE-640",
      "title": "Beetel 450TC3 password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82487"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-82540",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System cust_searchfrm.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82540"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-82541",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System sup_edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82541"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-82545",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System sup_searchfrm.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82545"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-82552",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Foundation",
      "product": "Magma",
      "cwe": "CWE-404",
      "title": "Linux Foundation Magma gNB Termination ngap_amf.c denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82552"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-82553",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sambitraj",
      "product": "Student Management System",
      "cwe": "CWE-266",
      "title": "sambitraj Student Management System Student Dashboard student_dashboard.php mysqli_query improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82553"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-82554",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Queue Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Queue Management System add_customer.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82554"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-82556",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Forgejo",
      "cwe": "CWE-918",
      "title": "Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82556"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-82587",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82587"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-82589",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-404",
      "title": "Open5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_transfer denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82589"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-82656",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-22",
      "title": "Admidio before 5.0.12 Path Traversal via Photo ZIP Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82656"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-82488",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Beetel",
      "product": "450TC3",
      "cwe": "CWE-79",
      "title": "Beetel 450TC3 User Management cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82488"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11819",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11819 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12965",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12965 (Unknown Super Store Finder WordPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16061",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16061 (Unknown Rest Routes). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16259",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16259 (Unknown Uix UserCenter). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16600",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16600 (Unknown SmartAIPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16739",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16739 (Unknown Epeken All Kurir for Woocommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16947",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16947 (Unknown Total processing card payments for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17520",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17520 (Unknown Newsletters). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17522",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17522 (Unknown Newsletters). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18233",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18233 (Unknown MStore API). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18234",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18234 (Unknown MStore API). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19430",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19430 (Unknown Catfolders Document Gallery Pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76546",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76546 (Unknown User Profile Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76547",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76547 (Unknown User Profile Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76548",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76548 (Unknown User Profile Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76586",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76586 (Unknown Appointment Booking Calendar Plugin and Scheduling Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77007 (Unknown HEL Online Classroom: AI-powered Online Classrooms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77008",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77008 (Unknown HEL Online Classroom: AI-powered Online Classrooms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77010 (Unknown HEL Online Classroom: AI-powered Online Classrooms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77012 (Unknown 爱采集数据采集和发布插件). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77704",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77704 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77786",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77786 (Unknown Rank Math SEO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80311",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80311 (Unknown Stripe Payment Forms by WP Full Pay). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80488 (Unknown WP Ultimate CSV Importer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81026",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81026 (Unknown MasterStudy LMS WordPress Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81200",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81200 (Unknown MasterStudy LMS WordPress Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81342",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81342 (Unknown MasterStudy LMS WordPress Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81346",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81346 (Unknown Frontend Admin by DynamiApps). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2019-1068",
      "detail": "DUE DATE PASSED — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). CISA remediation deadline was August 29, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-8452",
      "detail": "DUE DATE PASSED — CVE-2026-8452 (NetScaler ADC). CISA remediation deadline was August 29, 2026; still in catalog."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-14324",
      "detail": "PATCH SHIPPED — CVE-2026-14324 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:1.4.11-1.el10_2.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-14330",
      "detail": "PATCH SHIPPED — CVE-2026-14330 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:1.4.11-1.el9_8.2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71217",
      "detail": "PATCH SHIPPED — CVE-2026-71217 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 0:3.5-12.el8_10.1."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
