{
  "day": "2026-08-31",
  "boundary": "UTC calendar day",
  "published_count": 357,
  "by_severity": {
    "CRITICAL": 35,
    "HIGH": 95,
    "MEDIUM": 97,
    "LOW": 53
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 77,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-49003",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02399,
      "epss_percentile": 0.82851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "ZXDU68 S202 V5.0",
      "cwe": "CWE-287",
      "title": "Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49003"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-82668",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01657,
      "epss_percentile": 0.74922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klaussilveira",
      "product": "GitList",
      "cwe": "CWE-77",
      "title": "klaussilveira GitList Git Command Line CommandLine.php getDefaultBranch os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82668"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-82854",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01134,
      "epss_percentile": 0.64201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-93",
      "title": "Nodemailer before 8.0.3 SMTP Command Injection via envelope.size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82854"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-82597",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01131,
      "epss_percentile": 0.64145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "NR1800X",
      "cwe": "CWE-74",
      "title": "TOTOLINK NR1800X cstecgi.cgi setUssd command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82597"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-82669",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00741,
      "epss_percentile": 0.52122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klaussilveira",
      "product": "GitList",
      "cwe": "CWE-404",
      "title": "klaussilveira GitList XML Parsing CommandLine.php SimpleXMLElement denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82669"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-82853",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00735,
      "epss_percentile": 0.51911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-93",
      "title": "Nodemailer before 8.0.5 SMTP Command Injection via CRLF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82853"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-82616",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00613,
      "epss_percentile": 0.4692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "NR1800X",
      "cwe": "CWE-119",
      "title": "TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82616"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-82673",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00586,
      "epss_percentile": 0.45647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_admin",
      "cwe": "CWE-22",
      "title": "Path traversal in AshAdmin file uploads via unsanitized client filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82673"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-82665",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00436,
      "epss_percentile": 0.36366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yaojingang",
      "product": "GEOFlow",
      "cwe": "CWE-22",
      "title": "yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82665"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-82623",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "open62541",
      "cwe": "CWE-119",
      "title": "open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82623"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-82630",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.31858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PowerJob",
      "cwe": "CWE-918",
      "title": "PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82630"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-82621",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.31691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soarkey",
      "product": "StudentManagement",
      "cwe": "CWE-285",
      "title": "Soarkey StudentManagement/学生信息管理系统 Administrative Servlet AdminDao.java AdminDao.doGet authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82621"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-77956",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.30978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_ai",
      "cwe": "CWE-94",
      "title": "EEx template evaluation of prompt content in AshAi enables remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77956"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-82666",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00374,
      "epss_percentile": 0.30336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yaojingang",
      "product": "GEOFlow",
      "cwe": "CWE-74",
      "title": "yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82666"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-82631",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00358,
      "epss_percentile": 0.28753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valkey-io",
      "product": "valkey",
      "cwe": "CWE-119",
      "title": "valkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82631"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-82667",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00342,
      "epss_percentile": 0.26909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yaojingang",
      "product": "GEOFlow",
      "cwe": "CWE-918",
      "title": "yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82667"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-82664",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00341,
      "epss_percentile": 0.26819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yaojingang",
      "product": "GEOFlow",
      "cwe": "CWE-79",
      "title": "yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82664"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-82610",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.26753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82610"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-82611",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.26753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82611"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-58574",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.26294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-306",
      "title": "Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58574"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-68951",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GROWI, Inc.",
      "product": "GROWI",
      "cwe": "CWE-863",
      "title": "GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68951"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-81624",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.25778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-770",
      "title": "Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81624"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-82604",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BareBones",
      "product": "BBEdit",
      "cwe": "CWE-404",
      "title": "BareBones BBEdit Java Language recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82604"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-82605",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BareBones",
      "product": "BBEdit",
      "cwe": "CWE-404",
      "title": "BareBones BBEdit Lasso Language Tokenizer infinite loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82605"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-82855",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00326,
      "epss_percentile": 0.25153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hulumi",
      "product": "policies",
      "cwe": "CWE-693",
      "title": "@hulumi/policies before 1.3.2 Evidence Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82855"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-82598",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-74",
      "title": "SeaCMS Template search.php parseIf code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82598"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-82624",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Simple Inventory System",
      "cwe": "CWE-200",
      "title": "code-projects Simple Inventory System Database Backup File inventorymanagement.sql information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82624"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-82564",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_ai",
      "cwe": "CWE-639",
      "title": "Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82564"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-82599",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0031,
      "epss_percentile": 0.23306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-22",
      "title": "SeaCMS Avatar Upload member.php unlink path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82599"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-82602",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.22948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-285",
      "title": "SeaCMS ass.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82602"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-82629",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00306,
      "epss_percentile": 0.22766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeecgboot",
      "product": "jeewx-boot",
      "cwe": "CWE-284",
      "title": "jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82629"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2024-58379",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.22611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-1333",
      "title": "nodemailer before 6.9.9 ReDoS via attachDataUrls parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58379"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-81852",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00304,
      "epss_percentile": 0.22554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_admin",
      "cwe": "CWE-330",
      "title": "AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81852"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-82603",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00304,
      "epss_percentile": 0.22569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-22",
      "title": "SeaCMS Comment Cache member.php del_pl path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82603"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-82619",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00303,
      "epss_percentile": 0.22436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Systerel",
      "product": "S2OPC",
      "cwe": "CWE-119",
      "title": "Systerel S2OPC subscription_mgr.c use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82619"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-82859",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-284",
      "title": "hulumi before v1.3.2 SCP Template Tag-on-Create Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82859"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-82860",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hulumi",
      "product": "policies",
      "cwe": "CWE-269",
      "title": "@hulumi/policies before 1.3.2 Admin Policy Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82860"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-75757",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_admin",
      "cwe": "CWE-565",
      "title": "AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75757"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-82726",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_phoenix",
      "cwe": "CWE-178",
      "title": "AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82726"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-53620",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.20945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GROWI, Inc.",
      "product": "GROWI",
      "cwe": "CWE-639",
      "title": "GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53620"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-82607",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.20896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Profile Builder Plugin",
      "cwe": "CWE-284",
      "title": "Cozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simple_avatar unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82607"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-82856",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.20524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hulumi",
      "product": "policies",
      "cwe": "CWE-284",
      "title": "@hulumi/policies before 1.3.2 OIDC Trust Policy Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82856"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-82857",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.20522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-269",
      "title": "hulumi before v1.3.2 Privilege Escalation via IAM Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82857"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-75760",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_ai",
      "cwe": "CWE-209",
      "title": "AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75760"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-77850",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.19817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_admin",
      "cwe": "CWE-79",
      "title": "Stored XSS in AshAdmin relationship typeahead via unescaped label_field content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77850"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-82601",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00278,
      "epss_percentile": 0.19859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-79",
      "title": "SeaCMS err.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82601"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-82618",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.19664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Systerel",
      "product": "S2OPC",
      "cwe": "CWE-119",
      "title": "Systerel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82618"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-82625",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Simple Inventory System",
      "cwe": "CWE-79",
      "title": "code-projects Simple Inventory System User Registration register.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82625"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-82615",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82615"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82722",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.18593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_admin",
      "cwe": "CWE-770",
      "title": "AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82722"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-82579",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.18592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_ai",
      "cwe": "CWE-835",
      "title": "AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82579"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-82580",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.18592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_ai",
      "cwe": "CWE-209",
      "title": "AshAi echoes raw tool exception messages into the conversation, disclosing internal details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82580"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-82727",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00268,
      "epss_percentile": 0.18592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_phoenix",
      "cwe": "CWE-209",
      "title": "AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82727"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-82681",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00268,
      "epss_percentile": 0.18593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_admin",
      "cwe": "CWE-116",
      "title": "Query-parameter injection in AshAdmin row-action links via unencoded string primary keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82681"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-82612",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82612"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-82613",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Product Search index.php loadResultList sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82613"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-82614",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Product Category Filter index.php loadResultList sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82614"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-82872",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-639",
      "title": "ToolJet before v3.16.208 Cross-Workspace Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82872"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-81853",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_admin",
      "cwe": "CWE-639",
      "title": "AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81853"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-82725",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_phoenix",
      "cwe": "CWE-639",
      "title": "AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82725"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-82874",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00257,
      "epss_percentile": 0.17172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-639",
      "title": "ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82874"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-82861",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.16994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hulumi",
      "product": "policies",
      "cwe": "CWE-284",
      "title": "@hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82861"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-82659",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.16669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-73",
      "title": "nodemailer before 9.0.1 File Read and SSRF via raw option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82659"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-82600",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.16704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-74",
      "title": "SeaCMS zyapi.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82600"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-82864",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdfme",
      "product": "pdf-lib",
      "cwe": "CWE-409",
      "title": "pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82864"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-82724",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.15695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_phoenix",
      "cwe": "CWE-863",
      "title": "Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82724"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-58301",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro",
      "cwe": "CWE-918",
      "title": "Apache Shiro: Server-side POST request may be steered to an alternate host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58301"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-82838",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "venueless",
      "cwe": "CWE-80",
      "title": "Default webserver configuration with incorrect CSP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82838"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-82608",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00234,
      "epss_percentile": 0.14106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Kamailio",
      "cwe": "CWE-119",
      "title": "Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82608"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-82869",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-639",
      "title": "ToolJet Database before v3.16.44 Privilege Escalation via join_tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82869"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-82871",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-862",
      "title": "ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82871"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-82870",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-639",
      "title": "ToolJet before v3.16.208 Cross-Tenant Database Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82870"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-82866",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.1201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdfme",
      "product": "common",
      "cwe": "CWE-918",
      "title": "@pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82866"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-82620",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soarkey",
      "product": "StudentManagement",
      "cwe": "CWE-74",
      "title": "Soarkey StudentManagement/学生信息管理系统 CourseDao.java CourseDao.course_ranking sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82620"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-82609",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System inv_edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82609"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-82622",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.0967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Leave Managing System",
      "cwe": "CWE-79",
      "title": "code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82622"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-19410",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00197,
      "epss_percentile": 0.09514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Google Cloud Build",
      "cwe": "CWE-345",
      "title": "Google Cloud Build Comment Control Bypass via Webhook Suppression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19410"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-81315",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_ai",
      "cwe": "CWE-346",
      "title": "MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81315"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-82661",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-93",
      "title": "Nodemailer CRLF Injection via List-* Header Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82661"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-82660",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-862",
      "title": "Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82660"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-82858",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00188,
      "epss_percentile": 0.08498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hulumi",
      "product": "drift",
      "cwe": "CWE-345",
      "title": "@hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82858"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-82867",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.07905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdfme",
      "product": "schemas",
      "cwe": "CWE-79",
      "title": "@pdfme/schemas before 5.5.9 Cross-Site Scripting via Select",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82867"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-82873",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-639",
      "title": "ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82873"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-82671",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IObit",
      "product": "Unlocker",
      "cwe": "CWE-266",
      "title": "IObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82671"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-82868",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.04929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdfme",
      "product": "schemas",
      "cwe": "CWE-79",
      "title": "@pdfme/schemas before 5.5.9 Cross-Site Scripting via SVG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82868"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-82863",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hulumi",
      "product": "baseline",
      "cwe": "CWE-778",
      "title": "@hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82863"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-82670",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IObit",
      "product": "Uninstaller",
      "cwe": "CWE-266",
      "title": "IObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82670"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-40463",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "WaveSuite",
      "cwe": "CWE-284",
      "title": "An Insufficient Role-based Access Control Vulnerability in WaveSuite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40463"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-40465",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "NSP",
      "cwe": "CWE-601",
      "title": "An Open Re-direct Vulnerability in Nokia NSP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40465"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-82875",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-863",
      "title": "ToolJet before v3.16.208 Authorization Bypass via organizationId",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82875"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-40464",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "NSP",
      "cwe": "CWE-79",
      "title": "A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40464"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-77013",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "爱采集数据采集和发布插件",
      "cwe": "CWE-862",
      "title": "Icollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted Method Dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77013"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-82862",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.02988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-426",
      "title": "Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82862"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-82865",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00127,
      "epss_percentile": 0.0263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdfme",
      "product": "schemas",
      "cwe": "CWE-79",
      "title": "pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Label",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82865"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-82662",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-295",
      "title": "Nodemailer before 8.0.8 TLS Certificate Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82662"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-82628",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00117,
      "epss_percentile": 0.01843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Colorful",
      "product": "iGameCenter",
      "cwe": "CWE-266",
      "title": "Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82628"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-82596",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "LatencyUtils",
      "cwe": "CWE-119",
      "title": "LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82596"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-81779",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silk Themes",
      "product": "Newspapers X",
      "cwe": "CWE-1284",
      "title": "WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81779"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-81780",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hashthemes",
      "product": "Hash Form",
      "cwe": "CWE-434",
      "title": "WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81780"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-82970",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Legal Pages",
      "product": "WP Cookie Notice for GDPR, CCPA & ePrivacy Consent",
      "cwe": "CWE-434",
      "title": "WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82970"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-79748",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-862",
      "title": "MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79748"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-82226",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tickera",
      "product": "Tickera",
      "cwe": "CWE-502",
      "title": "WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82226"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-53552",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhenorzz",
      "product": "goploy",
      "cwe": "CWE-639",
      "title": "Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53552"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-59111",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ministry of the Interior (MVČR)",
      "product": "eObčanka-Identifikace",
      "cwe": "CWE-78",
      "title": "Command Injection vulnerability in eObčanka-Identifikace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59111"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-73819",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NA111-M Firmware",
      "cwe": "CWE-1390",
      "title": "Ebyte NA111-M Weak Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73819"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-76133",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NA111-M Firmware",
      "cwe": "CWE-327",
      "title": "Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76133"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-81293",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Passionate Programmer Peter",
      "product": "WP Data Access",
      "cwe": "CWE-89",
      "title": "WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81293"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-81756",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autorius E-goi",
      "product": "Smart Marketing SMS and Newsletters Forms",
      "cwe": "CWE-89",
      "title": "WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81756"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-81763",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ウェブ屋のさとーさん",
      "product": "Throws SPAM Away",
      "cwe": "CWE-89",
      "title": "WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81763"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-82693",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC1206",
      "cwe": "CWE-287",
      "title": "Tenda AC1206 Web UI telnet TendaTelnet missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82693"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-82694",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC1206",
      "cwe": "CWE-287",
      "title": "Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82694"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-82695",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC18",
      "cwe": "CWE-287",
      "title": "Tenda AC18 Telnet telnet missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82695"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-82876",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phison Electronics Corporation",
      "product": "PS3111-S11 Controller Firmware",
      "cwe": "CWE-347",
      "title": "Phison PS3111-S11 Controller Firmware Signature Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82876"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-82971",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QVidium",
      "product": "Opera11",
      "cwe": "CWE-74",
      "title": "QVidium Opera11 CGI Script net_tr.cgi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82971"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-66047",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Proper Fraction",
      "product": "ProfilePress",
      "cwe": "CWE-306",
      "title": "ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66047"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-51679",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51679"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-51680",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51680"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-51681",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51681"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-51720",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51720"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-51725",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51725"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-51730",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51730"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-78078",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix Ultimate extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78078"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-5956",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ankara Hosting",
      "product": "Site Management Panel",
      "cwe": "CWE-89",
      "title": "SQLi in Ankara Hosting's Site Management Panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5956"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-12894",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel 4 for Quarkus 3",
      "cwe": "CWE-1336",
      "title": "Quarkus-qute: io.quarkus.qute.reflectionvalueresolver: quarkus:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12894"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-78074",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniorgange.com",
      "product": "miniOrange Oauth Client (free) extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78074"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-79744",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-269",
      "title": "MCPHub: Missing Authorization on `PUT /api/system-config` Lets Any Non-Admin Rewrite Global Security Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79744"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-82217",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-22",
      "title": "In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI \"Agent Mode\" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path, or a ~-expanded path could therefore write or delete files outside the workspace with the privileges of the Theia backend OS user. Because the path argument is influenced by model output, it can be steered through indirect prompt injection, and in Agent Mode writes are applied without a confirmation dialog. Writing to a host-executed file such as a shell startup file or ~/.ssh/authorized_keys can escalate to code execution on the backend.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82217"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-83596",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-120",
      "title": "Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83596"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-75133",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fahad Mahmood",
      "product": "Keep Backup Daily",
      "cwe": "CWE-306",
      "title": "Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75133"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-77966",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NA111-M Firmware",
      "cwe": "CWE-862",
      "title": "Ebyte NA111-M Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77966"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-82880",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yacy",
      "product": "yacy_search_server",
      "cwe": "CWE-611",
      "title": "YaCy Search Server through 1.941 XML External Entity Injection via Parsers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82880"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-82882",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devtron-labs",
      "product": "devtron",
      "cwe": "CWE-862",
      "title": "Devtron through 2.2.0 Missing Authorization via webhook API token endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82882"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-83497",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSearch",
      "product": "OpenSearch",
      "cwe": "CWE-502",
      "title": "Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83497"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-72001",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pangolin",
      "product": "Pangolin",
      "cwe": "CWE-639",
      "title": "Pangolin < 1.22.0 Authentication Bypass via Share-Link Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72001"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-78077",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix Ultimate extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78077"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-81889",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Studio-42",
      "product": "elFinder",
      "cwe": "CWE-918",
      "title": "elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81889"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-82689",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320L",
      "cwe": "CWE-77",
      "title": "D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82689"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-82692",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-340L",
      "cwe": "CWE-77",
      "title": "D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82692"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-82954",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Dokploy",
      "cwe": "CWE-22",
      "title": "Dokploy Settings application.ts writeTraefikConfigInPath path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82954"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-83524",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RedPort",
      "product": "Optimizer wXa-203",
      "cwe": "CWE-74",
      "title": "RedPort Optimizer wXa-223 System Clock datetime.php exec command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83524"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-61639",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-22",
      "title": "Wallos: Zip Slip path traversal in database restore writes files to webroot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61639"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-61640",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-918",
      "title": "Wallos: SSRF via OIDC Token/UserInfo URL Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61640"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-81287",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "Charitable",
      "cwe": "CWE-89",
      "title": "WordPress Charitable plugin <= 1.8.12.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81287"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-82688",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-340L",
      "cwe": "CWE-77",
      "title": "D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82688"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-82690",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-327L",
      "cwe": "CWE-77",
      "title": "D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82690"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-82691",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320L",
      "cwe": "CWE-77",
      "title": "D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82691"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-82807",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ieungSoft",
      "product": "Ultra RAMDisk Pro",
      "cwe": "CWE-266",
      "title": "ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82807"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-82908",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Dragon Center",
      "cwe": "CWE-189",
      "title": "MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82908"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-53507",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oasdiff",
      "product": "oasdiff-action",
      "cwe": "CWE-200",
      "title": "oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53507"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-54600",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-287",
      "title": "Wallos: Unauthenticated database replacement via import endpoint on fresh install",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54600"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-61638",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-918",
      "title": "Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61638"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-75594",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-22",
      "title": "Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75594"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-77348",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-441",
      "title": "Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77348"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-61641",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-287",
      "title": "Wallos: OIDC account takeover via email-based account linking without `email_verified` check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61641"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-79746",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-863",
      "title": "MCPHub: Server-scoped bearer key gains access to an entire group via partial (any-overlap) server matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79746"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-81891",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Studio-42",
      "product": "elFinder",
      "cwe": "CWE-434",
      "title": "elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81891"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-81892",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EasyCorp",
      "product": "EasyAdminBundle",
      "cwe": "CWE-639",
      "title": "EasyAdmin custom-action dispatcher bypasses access_control on other routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81892"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-82228",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SiteGround",
      "product": "SiteGround Security",
      "cwe": "CWE-290",
      "title": "WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82228"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-13732",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13732"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-19702",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TÜBİTAK BİLGEM Software Technologies Research Institute",
      "product": "Pardus Boot Repair",
      "cwe": "CWE-78",
      "title": "OS Command Injection in TÜBİTAK BİLGEM's Pardus Boot Repair",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19702"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-53553",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhenorzz",
      "product": "goploy",
      "cwe": "CWE-22",
      "title": "Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53553"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-79750",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-639",
      "title": "MCPHub authenticated horizontal IDOR: any non-admin user executes tools on other users' MCP servers (cross-tenant file read + SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79750"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-79749",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-918",
      "title": "MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79749"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-17615",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel 4 for Quarkus 3",
      "cwe": "CWE-611",
      "title": "Resteasy-core: resteasy sourceprovider remote unauthenticated file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17615"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-19616",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TBC Technology Inc.",
      "product": "KitLogistic",
      "cwe": "CWE-862",
      "title": "Information Disclosure in TBC Technology's KitLogistic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19616"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-19873",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "HTML-FormFu",
      "cwe": "CWE-770",
      "title": "HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19873"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-54598",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in wallos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54598"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-54599",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-352",
      "title": "Wallos: OIDC state parameter never validated — login CSRF / account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54599"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-76763",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Quarkus",
      "cwe": "CWE-1284",
      "title": "Io.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of service via large exponent float literals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76763"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-81296",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "Fluent Forms Pro Add On Pack",
      "cwe": "CWE-862",
      "title": "WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81296"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-81297",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "Fluent Forms Pro Add On Pack",
      "cwe": "CWE-266",
      "title": "WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81297"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-82393",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82393"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-82397",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tornadoweb",
      "product": "tornado",
      "cwe": "CWE-400",
      "title": "Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82397"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-82225",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metagauss",
      "product": "RegistrationMagic",
      "cwe": "CWE-288",
      "title": "WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82225"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-82680",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DSM-G600",
      "cwe": "CWE-119",
      "title": "D-Link DSM-G600 Multipart load_file.cgi out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82680"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-78422",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "z-galaxy",
      "product": "zbus_polkit",
      "cwe": "CWE-367",
      "title": "zbus_polkit: polkit authorization bypass via PID reuse due to incorrect D-Bus type for the subject UID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78422"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-71415",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-862",
      "title": "Kirby: File upload permissions are not checked during processing of chunk data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71415"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-75132",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tranquil_IT",
      "product": "WAPT",
      "cwe": "CWE-89",
      "title": "WAPT Server SQL Injection via /api/v3/hosts Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75132"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-77975",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ebyte",
      "product": "Ebyte NE2-D11 Firmware",
      "cwe": "CWE-312",
      "title": "Ebyte NA111-M Cleartext Storage of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77975"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-79745",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-862",
      "title": "MCPHub: Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorized Tampering of Globally-Served Templates/Resources)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79745"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-79747",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-918",
      "title": "MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy + transport dial)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79747"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-81290",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Icegram",
      "product": "Email Subscribers & Newsletters",
      "cwe": "CWE-79",
      "title": "WordPress Email Subscribers & Newsletters plugin <= 5.9.33 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81290"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-81291",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uncode",
      "product": "Uncode",
      "cwe": "CWE-79",
      "title": "WordPress Uncode theme <= 2.12.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81291"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-81298",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "varunvairavanlc",
      "product": "LeadConnector",
      "cwe": "CWE-79",
      "title": "WordPress LeadConnector plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81298"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-81764",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acato",
      "product": "Email Essentials",
      "cwe": "CWE-79",
      "title": "WordPress Email Essentials plugin <= 6.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81764"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-81765",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tailored Media",
      "product": "Tailored Tools",
      "cwe": "CWE-79",
      "title": "WordPress Tailored Tools plugin <= 3.0.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81765"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-81768",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "highwarden",
      "product": "Super Store Finder",
      "cwe": "CWE-79",
      "title": "WordPress Super Store Finder plugin <= 7.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81768"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-82221",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metagauss",
      "product": "RegistrationMagic",
      "cwe": "CWE-79",
      "title": "WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82221"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-82224",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iova.mihai",
      "product": "SliceWP",
      "cwe": "CWE-79",
      "title": "WordPress SliceWP plugin <= 1.2.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82224"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-82229",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "WordPress Social Login and Register",
      "cwe": "CWE-79",
      "title": "WordPress WordPress Social Login and Register plugin <= 7.8.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82229"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-82392",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82392"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-82877",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ILIAS-eLearning e.V.",
      "product": "ILIAS",
      "cwe": "CWE-22",
      "title": "ILIAS before 9.22 Arbitrary File Read via SOAP addFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82877"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-82346",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP ImageDiags",
      "cwe": "CWE-379",
      "title": "HP ImageDiags - Potential Escalation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82346"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-62993",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smarty-php",
      "product": "smarty",
      "cwe": "CWE-918",
      "title": "Smarty: SSRF via redirect bypass of trusted_uri using {fetch}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62993"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-75592",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-22",
      "title": "Kirby: Access to image files outside of the site root via path traversal in the media handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75592"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-79743",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-22",
      "title": "MCPHub: Path Traversal via Malicious MCPB Manifest Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79743"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-82398",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-407",
      "title": "pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82398"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-83492",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extend Themes",
      "product": "Kubio AI Website Builder",
      "cwe": "CWE-20",
      "title": "WordPress Kubio AI Website Builder - Denial Of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83492"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-14696",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-401",
      "title": "Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14696"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-14697",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-401",
      "title": "IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14697"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-81280",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UKR Solution",
      "product": "Print Barcode Labels for your WooCommerce products/orders",
      "cwe": "CWE-201",
      "title": "WordPress Print Barcode Labels for your WooCommerce products/orders plugin <= 4.0.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81280"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-81762",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Booking and Rental Manager",
      "cwe": "CWE-862",
      "title": "WordPress Booking and Rental Manager plugin <= 2.7.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81762"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-81778",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The4",
      "product": "Kalles Addons",
      "cwe": "CWE-79",
      "title": "WordPress Kalles Addons plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81778"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2023-20511",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Radeon™ Instinct™ MI25 Graphics Products",
      "cwe": "CWE-763",
      "title": "Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-20511"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-14366",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pkt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14366"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-81758",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OwnerRez",
      "product": "OwnerRez API",
      "cwe": "CWE-862",
      "title": "WordPress OwnerRez API plugin <= 1.2.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81758"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-76986",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-79",
      "title": "Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76986"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-53508",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oasdiff",
      "product": "oasdiff",
      "cwe": "CWE-73",
      "title": "oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53508"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-82698",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sambitraj",
      "product": "Student-Management-System",
      "cwe": "CWE-1393",
      "title": "sambitraj Student-Management-System aca.sql default password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82698"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-82701",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Shopping System",
      "cwe": "CWE-74",
      "title": "code-projects Online Shopping System Search Functionality action.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82701"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-82797",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82797"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-82801",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "earthdata-search",
      "cwe": "CWE-918",
      "title": "NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82801"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-82802",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "earthdata-search",
      "cwe": "CWE-918",
      "title": "NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82802"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-82803",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "armink",
      "product": "struct2json",
      "cwe": "CWE-404",
      "title": "armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82803"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-82808",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inbox Foundry",
      "product": "ActiveInbox Extension",
      "cwe": "CWE-259",
      "title": "Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82808"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-82815",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MegaEase",
      "product": "EaseProbe",
      "cwe": "CWE-266",
      "title": "MegaEase EaseProbe Middleware server.go realIP access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82815"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-82914",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kishan0725",
      "product": "Hospital-Management-System",
      "cwe": "CWE-74",
      "title": "kishan0725 Hospital-Management-System search.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82914"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-82919",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cu",
      "product": "silicon",
      "cwe": "CWE-287",
      "title": "cu silicon edit Endpoint views.py create_app missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82919"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-82921",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShopEx",
      "product": "ECShop",
      "cwe": "CWE-284",
      "title": "ShopEx ECShop pack.php check_img_type unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82921"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-82922",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShopEx",
      "product": "ECShop",
      "cwe": "CWE-74",
      "title": "ShopEx ECShop flow.php flow_update_cart sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82922"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-82957",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hyperledger-firefly",
      "product": "firefly",
      "cwe": "CWE-918",
      "title": "hyperledger-firefly Webhook Subscription webhooks.go ValidateOptions server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82957"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-14368",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-193",
      "title": "Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14368"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-81267",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-451",
      "title": "Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81267"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-81278",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPExperts",
      "product": "Post SMTP",
      "cwe": "CWE-862",
      "title": "WordPress Post SMTP plugin 4.0.0-beta.1 - Settings Change vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81278"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-81888",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "@hono/oauth-providers",
      "cwe": "CWE-352",
      "title": "@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81888"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-81890",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Studio-42",
      "product": "elFinder",
      "cwe": "CWE-352",
      "title": "elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81890"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-82396",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sulu",
      "product": "sulu",
      "cwe": "CWE-79",
      "title": "Sulu: Stored XSS via media download inline-disposition override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82396"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-82852",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MapSVG",
      "product": "MapSVG",
      "cwe": "CWE-918",
      "title": "WordPress MapSVG plugin <= 8.15.0 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82852"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-70449",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-22",
      "title": "Apache Wicket: Path traversal in resource style/variation/locale",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70449"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-74010",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "John James Jacoby",
      "product": "bbPress",
      "cwe": "CWE-862",
      "title": "WordPress bbPress plugin <= 2.6.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74010"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-78079",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix Ultimate extension for Joomla",
      "cwe": "CWE-601",
      "title": "Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78079"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-82394",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sulu",
      "product": "sulu",
      "cwe": "CWE-862",
      "title": "Sulu: Fix authorization bypass when creating preview links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82394"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-82395",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sulu",
      "product": "sulu",
      "cwe": "CWE-639",
      "title": "Sulu: Media move/update authorization bypass (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82395"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-82878",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-862",
      "title": "DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Chart Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82878"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-82879",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-863",
      "title": "DataEase before 2.10.26 Access Control Bypass via Share Tickets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82879"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-75802",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-79",
      "title": "Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75802"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-76982",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-79",
      "title": "Apache Wicket: XSS in Button via its model object",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76982"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-76983",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-79",
      "title": "Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76983"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-76984",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-79",
      "title": "Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76984"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-76985",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-79",
      "title": "Apache Wicket: XSS in Palette via getAdditionalAttributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76985"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-78075",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix Ultimate extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78075"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-78076",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix Ultimate extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78076"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-81887",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livewire",
      "product": "livewire",
      "cwe": "CWE-79",
      "title": "Livewire DOM-based cross-site scripting during client-side state handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81887"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-82881",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apconw",
      "product": "Aix-DB",
      "cwe": "CWE-79",
      "title": "Aix-DB through 1.2.4 Stored Cross-Site Scripting via Markdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82881"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-71378",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-352",
      "title": "Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71378"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-77353",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-74",
      "title": "Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77353"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-54179",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-79",
      "title": "backpack/crud: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public disk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54179"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-50198",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-639",
      "title": "Wallos: Cross-user subscription cost inference via replacement_subscription_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50198"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-50199",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-863",
      "title": "Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50199"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-52730",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xibosignage",
      "product": "xibo-cms",
      "cwe": "CWE-862",
      "title": "Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52730"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-77352",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-918",
      "title": "Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77352"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-77351",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellite",
      "product": "Wallos",
      "cwe": "CWE-918",
      "title": "Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77351"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2023-31308",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Radeon™ PRO V620 Graphics Products",
      "cwe": "CWE-129",
      "title": "A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-31308"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-14367",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-362",
      "title": "I3C IBI work-node free-list data race between ISR and workqueue thread",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14367"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-21827",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Connections",
      "cwe": "CWE-359",
      "title": "HCL Connections is vulnerable to an information disclosure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21827"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-82697",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sambitraj",
      "product": "Student-Management-System",
      "cwe": "CWE-732",
      "title": "sambitraj Student-Management-System session_start cookie httponly flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82697"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-82906",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sdcb",
      "product": "chats",
      "cwe": "CWE-287",
      "title": "sdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82906"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-82679",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "diem-project",
      "product": "diem",
      "cwe": "CWE-284",
      "title": "diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82679"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-82696",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System inv_searchfrm.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82696"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-82700",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Shopping System",
      "cwe": "CWE-79",
      "title": "code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82700"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-82805",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Typora",
      "cwe": "CWE-79",
      "title": "Typora Mermaid Rendering cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82805"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-82809",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vidIQ",
      "product": "Vision for YouTube Extension",
      "cwe": "CWE-200",
      "title": "vidIQ Vision for YouTube Extension postMessage window.addEventListener information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82809"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-82811",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toggl OÜ",
      "product": "Toggl Track Extension",
      "cwe": "CWE-345",
      "title": "Toggl OÜ Toggl Track Extension postMessage origin validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82811"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-82813",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BEN Group",
      "product": "TubeBuddy for YouTube Extension",
      "cwe": "CWE-345",
      "title": "BEN Group TubeBuddy for YouTube Extension tubebuddymaster1.js TBGlobal.GetToken data authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82813"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-82816",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dibo-software",
      "product": "diboot",
      "cwe": "CWE-285",
      "title": "dibo-software diboot AI Session Endpoint ai-session authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82816"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-82817",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dibo-software",
      "product": "diboot",
      "cwe": "CWE-266",
      "title": "dibo-software diboot Tenant Administrator Management API admin access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82817"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-82818",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dibo-software",
      "product": "diboot",
      "cwe": "CWE-266",
      "title": "dibo-software diboot Tenant Resource Assignment resource access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82818"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-82820",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FLVMeta",
      "cwe": "CWE-119",
      "title": "FLVMeta AMF String Processing amf.c amf_string_new heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82820"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-82821",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FLVMeta",
      "cwe": "CWE-404",
      "title": "FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82821"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-82833",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Doccano",
      "product": "Open Source Annotation Tools for Machine Learning Practitioners",
      "cwe": "CWE-266",
      "title": "Doccano Open Source Annotation Tools for Machine Learning Practitioners Project Example Detail Endpoint examples ExampleDetail access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82833"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-82834",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Doccano",
      "product": "Open Source Annotation Tools for Machine Learning Practitioners",
      "cwe": "CWE-266",
      "title": "Doccano Open Source Annotation Tools for Machine Learning Practitioners Bulk-Delete Endpoint category-types LabelList access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82834"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-82835",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caoqianming",
      "product": "django-vue-admin",
      "cwe": "CWE-266",
      "title": "caoqianming django-vue-admin file access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82835"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-82905",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sdcb",
      "product": "chats",
      "cwe": "CWE-918",
      "title": "sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82905"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-82909",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-613",
      "title": "QuantumNous new-api Revoked API Token token session expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82909"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-82678",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "diem-project",
      "product": "diem",
      "cwe": "CWE-77",
      "title": "diem-project diem Administrative Console actions.class.php executeCommand os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82678"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-82699",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sambitraj",
      "product": "Student Management System",
      "cwe": "CWE-310",
      "title": "sambitraj Student Management System Password aca.sql cleartext storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82699"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-82702",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6214K",
      "cwe": "CWE-77",
      "title": "Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82702"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-82703",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6214K",
      "cwe": "CWE-77",
      "title": "Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82703"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-82677",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valkey-io",
      "product": "valkey",
      "cwe": "CWE-119",
      "title": "valkey-io valkey Module Timer module.c moduleTimerHandler double free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82677"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-82810",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "extension.vn",
      "product": "2FA Authenticator Extension",
      "cwe": "CWE-200",
      "title": "extension.vn 2FA Authenticator Extension Background Service Worker chrome.runtime.onMessageExternal.addListener information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82810"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2025-63607",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63607"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-19953",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "URI",
      "cwe": "CWE-1289",
      "title": "URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19953"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-38577",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38577"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-51152",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HTTPRequest from user-supplied JSON without validating URL scheme, host, or IP range. The /har/test handler does not require authentication, enabling unauthenticated remote attackers to force the QD server to send arbitrary HTTP requests to internal network resources and cloud metadata endpoints. validate_cert is set to False, disabling TLS verification.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51152"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-51153",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/task.py in QD 20220208 through 20250803. When a task is run via /task/<taskid>/run, the handler renders task log content (logtmp) into the HTML response using Python % string formatting without HTML encoding. logtmp is populated from the exception object or from new_env.variables.__log__, which is attacker-controlled via the template extract_variables mechanism. A low-privileged authenticated attacker can create a crafted HAR template that extracts arbitrary HTML/JavaScript into the __log__ variable via the api://util/unicode endpoint. When a victim triggers the task run, the embedded script executes in the victim browser within the QD application context.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51153"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-51666",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51666"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-51667",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51667"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-51668",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51668"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-51669",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51669"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-51670",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51670"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-51671",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51671"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-51672",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51672"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-51673",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51673"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-51674",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51674"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-51675",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51675"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-51676",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51676"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-51677",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51677"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-51678",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51678"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-51683",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51683"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-51684",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51684"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-51686",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51686"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-51687",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51687"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-51688",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51688"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-51689",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51689"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-51690",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51690"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-51691",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51691"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-51692",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51692"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-51693",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51693"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-51694",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51694"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-51695",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51695"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-51696",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51696"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-51697",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51697"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-51698",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51698"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-51699",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51699"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-51700",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51700"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-51701",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51701"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-51702",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51702"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-51703",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51703"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-51704",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51704"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-51705",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51705"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-51706",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51706"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-51708",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51708"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-51709",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51709"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-51710",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51710"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-51711",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51711"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-51712",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51712"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-51713",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51713"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-51714",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51714"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-51715",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51715"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-51716",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51716"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-51717",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51717"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-51718",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51718"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-51719",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51719"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-51721",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51721"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-51722",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51722"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-51723",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51723"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-51724",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51724"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-51726",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51726"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-51727",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51727"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-51728",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51728"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-51729",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51729"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-51731",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51731"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-51732",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51732"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-51733",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51733"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-51734",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51734"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-51735",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51735"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-51736",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51736"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-51737",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51737"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-51738",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51738"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-51739",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51739"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-51740",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51740"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-71257",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-770",
      "title": "Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71257"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-75458",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence, without any validation of whether the current user has the authority to delete the target user. An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a vertical privilege escalation where a lower-privileged user performs a high-privileged operation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75458"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-75460",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75460"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-79407",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME value with the settings directory and opens the resulting path without validating that the resolved path remains within the intended directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79407"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-79408",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79408"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-79483",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79483"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-81578",
      "detail": "ADDED TO KEV — CVE-2026-81578 (PaperCut MF/NG). Remediation due September 14, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-82078",
      "detail": "ADDED TO KEV — CVE-2026-82078 (PaperCut MF/NG). Remediation due September 14, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-6387",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-6387 (OpenSSH). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-13601",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-13601 (glib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-4598",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-5914",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-6021",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62718",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62718 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0989",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0989 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0990",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0990 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0992",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0992 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13479",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13479 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13480",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13480 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13481",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13481 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14307",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14307 (Unknown geotargetingwp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14835",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14835 (Unknown SOGO Add Script to Individual Pages Header Footer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-22244",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-22244 (open-metadata OpenMetadata). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32141",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33228",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33228 (WebReflection flatted). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33891",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33891 (digitalbazaar forge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33896 (digitalbazaar forge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33937",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33937 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33938",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33938 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3832",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59090",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59090 (gimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62382",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62382 (pglombardo PasswordPusher). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62385",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62385 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63310",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63310 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63312",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63312 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65915",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65915 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6732",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6732 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70626",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70626 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76585",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76585 (Unknown Customer Reviews for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76639 (Unitree Robotics G1 EDU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76882",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76882 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76883",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76883 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76884",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76884 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76885",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76885 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76889",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76889 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76890",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76890 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76891",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76891 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76917",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76917 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76918",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76918 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76919",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76919 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76920",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76920 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76921",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76921 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76922 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76923",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76923 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76927",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76927 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76928",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76928 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76929",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76929 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78364",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78364 (Unknown MW WP Form). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78682",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78682 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78683",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78683 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79657",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79657 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79674",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79674 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79676",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79676 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81578 (PaperCut MF/NG). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81660",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81660 (Unknown Groundhogg — CRM, Newsletters, and Marketing Automation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81722",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81722 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81724",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81724 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81726",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81726 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81727",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81727 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81766",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81766 (Unknown Really Simple Security). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81833 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81836",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81836 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81845",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81845 (arben-adm mcp-sequential-thinking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81934",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81934 (Redis). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82017",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82078",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82078 (PaperCut MF/NG). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82111",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82111 (iswalle getnote-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82280",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82280 (QuivrHQ quivr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82421",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82421 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82422",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82422 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82424",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82424 (PHPGurukul Student Information System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82473",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82473 (kubeedge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82483",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82483 (coppermine-gallery Coppermine Photo Gallery). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82484",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82484 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82485",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82485 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82488 (Beetel 450TC3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82540",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82540 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82541",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82541 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82543",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82543 (vastsa FileCodeBox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82545",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82545 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82549",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82549 (Linux Foundation Magma). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82550",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82550 (Linux Foundation Magma). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82551",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82551 (Linux Foundation Magma). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82552",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82552 (Linux Foundation Magma). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82554",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82554 (SourceCodester Queue Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82555",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82555 (TOTOLINK N600R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82556",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82556 (Forgejo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82587 (Open5GS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82589",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82589 (Open5GS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82592",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82592 (D-Link DIR-825M). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2023-49105",
      "detail": "DUE DATE PASSED — CVE-2023-49105. CISA remediation deadline was August 30, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-53362",
      "detail": "DUE DATE PASSED — CVE-2026-53362 (Linux). CISA remediation deadline was August 30, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-31104",
      "detail": "RESCORED — CVE-2025-31104 (Fortinet FortiADC). CVSS 7 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10053",
      "detail": "RESCORED — CVE-2026-10053 (GitLab). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-13479",
      "detail": "RESCORED — CVE-2026-13479 (zephyrproject zephyr). CVSS 3.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18252",
      "detail": "RESCORED — CVE-2026-18252 (GitLab). CVSS 7.3 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19294",
      "detail": "RESCORED — CVE-2026-19294 (IBM Langflow OSS). CVSS 6.4 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33896",
      "detail": "RESCORED — CVE-2026-33896 (digitalbazaar forge). CVSS 7.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57826",
      "detail": "RESCORED — CVE-2026-57826. CVSS 9.8 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58616",
      "detail": "RESCORED — CVE-2026-58616 (Microsoft Edge (Chromium-based)). CVSS 4.4 → 3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59291",
      "detail": "RESCORED — CVE-2026-59291 (Spring Cloud Function). CVSS 2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59294",
      "detail": "RESCORED — CVE-2026-59294 (Spring AI). CVSS 5.9 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59321",
      "detail": "RESCORED — CVE-2026-59321 (Spring Integration). CVSS 4.2 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73055",
      "detail": "RESCORED — CVE-2026-73055 (ericcornelissen shescape). CVSS 9.3 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76882",
      "detail": "RESCORED — CVE-2026-76882 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76883",
      "detail": "RESCORED — CVE-2026-76883 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76884",
      "detail": "RESCORED — CVE-2026-76884 (Wireshark Foundation Wireshark). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76885",
      "detail": "RESCORED — CVE-2026-76885 (Wireshark Foundation Wireshark). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76887",
      "detail": "RESCORED — CVE-2026-76887 (Wireshark Foundation Wireshark). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76889",
      "detail": "RESCORED — CVE-2026-76889 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76890",
      "detail": "RESCORED — CVE-2026-76890 (Wireshark Foundation Wireshark). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76891",
      "detail": "RESCORED — CVE-2026-76891 (Wireshark Foundation Wireshark). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76919",
      "detail": "RESCORED — CVE-2026-76919 (Wireshark Foundation Wireshark). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76920",
      "detail": "RESCORED — CVE-2026-76920 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76927",
      "detail": "RESCORED — CVE-2026-76927 (Wireshark Foundation Wireshark). CVSS 4.7 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76929",
      "detail": "RESCORED — CVE-2026-76929 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79088",
      "detail": "RESCORED — CVE-2026-79088 (Google Chrome). CVSS 5.4 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81934",
      "detail": "RESCORED — CVE-2026-81934 (Redis). CVSS 9.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82593",
      "detail": "RESCORED — CVE-2026-82593 (D-Link DIR-825M). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82594",
      "detail": "RESCORED — CVE-2026-82594 (LogNet grpc-spring-boot-starter). CVSS 2.3 → 1.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82595",
      "detail": "RESCORED — CVE-2026-82595 (D-Link DIR-825M). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16730",
      "detail": "PATCH SHIPPED — CVE-2026-16730 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:36-5.el10_2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-5704",
      "detail": "PATCH SHIPPED — CVE-2026-5704 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:1.34-13.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-59090",
      "detail": "PATCH SHIPPED — CVE-2026-59090 (gimp). Fixed in Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.10."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-59285",
      "detail": "ENRICHED — CVE-2026-59285 (Spring for GraphQL). Received CVSS 8.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-59286",
      "detail": "ENRICHED — CVE-2026-59286 (Spring for GraphQL). Received CVSS 8.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-59287",
      "detail": "ENRICHED — CVE-2026-59287 (Spring for GraphQL). Received CVSS 5.9 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-59288",
      "detail": "ENRICHED — CVE-2026-59288 (Spring for GraphQL). Received CVSS 7.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-59289",
      "detail": "ENRICHED — CVE-2026-59289 (Spring for GraphQL). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-59314",
      "detail": "ENRICHED — CVE-2026-59314 (Spring Framework). Received CVSS 3.7 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
