{
  "day": "2026-09-01",
  "boundary": "UTC calendar day",
  "published_count": 477,
  "by_severity": {
    "CRITICAL": 34,
    "HIGH": 194,
    "MEDIUM": 151,
    "LOW": 30
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 68,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-59680",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.02339,
      "epss_percentile": 0.8242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "yast2-users",
      "cwe": "CWE-78",
      "title": "yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59680"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-83772",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01687,
      "epss_percentile": 0.75408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cobham",
      "product": "SATCOM VSAT7090 Maritime Satellite Router",
      "cwe": "CWE-74",
      "title": "Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83772"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-67394",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01167,
      "epss_percentile": 0.65155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-78",
      "title": "A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67394"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-59681",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01149,
      "epss_percentile": 0.64632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "yast2-auth-client",
      "cwe": "CWE-78",
      "title": "yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD join",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59681"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-67395",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00839,
      "epss_percentile": 0.55328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sage",
      "product": "Employee Self Service",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended file system scope. Successful exploitation would require knowledge of valid file names and paths. Depending on the privileges of the affected component, exploitation could result in the disclosure of sensitive information, including configuration files, environment settings, application assets, and log data. The vulnerability has been remediated through enhanced path validation and secure path resolution controls that prevent access to unauthorised locations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67395"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-19952",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0078,
      "epss_percentile": 0.53429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-22",
      "title": "Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19952"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-65643",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00642,
      "epss_percentile": 0.48309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-95",
      "title": "Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65643"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-75921",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00628,
      "epss_percentile": 0.47676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixarlabs",
      "product": "Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits",
      "cwe": "CWE-863",
      "title": "Master Addons for Elementor <= 3.1.9 - Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75921"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-75865",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00513,
      "epss_percentile": 0.4165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wplegalpages",
      "product": "WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode",
      "cwe": "CWE-434",
      "title": "WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75865"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-19914",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uscnanbu",
      "product": "Welcart e-Commerce",
      "cwe": "CWE-79",
      "title": "Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19914"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-19032",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00463,
      "epss_percentile": 0.38373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-470",
      "title": "jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19032"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-25706",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "yast2-samba-client",
      "cwe": "CWE-78",
      "title": "yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25706"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-78319",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.33581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sauter",
      "product": "modu680-AS",
      "cwe": "CWE-367",
      "title": "TOCTOU Vulnerability in file exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78319"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-19806",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System",
      "cwe": "CWE-287",
      "title": "Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19806"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-19948",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozythemes",
      "product": "Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates",
      "cwe": "CWE-862",
      "title": "Cozy Blocks <= 2.2.17 - Missing Authorization to Unauthenticated Unpublished Product Information Disclosure via 'wishlistData' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19948"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-82732",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.31977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_typescript",
      "cwe": "CWE-20",
      "title": "Declared argument constraints not enforced on AshTypescript typed controller routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82732"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-77823",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-89",
      "title": "LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77823"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-76006",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.27984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ays-pro",
      "product": "Photo Gallery by Ays – Responsive Image Gallery",
      "cwe": "CWE-89",
      "title": "Photo Gallery by Ays <= 6.8.2 - Authenticated (Administrator+) SQL Injection via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76006"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-16786",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livecomposer",
      "product": "Live Composer – Free WordPress Website Builder",
      "cwe": "CWE-79",
      "title": "Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16786"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-16788",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livecomposer",
      "product": "Live Composer – Free WordPress Website Builder",
      "cwe": "CWE-79",
      "title": "Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_projects_output Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16788"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-18488",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creativethemeshq",
      "product": "Blocksy Companion",
      "cwe": "CWE-79",
      "title": "Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18488"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-19820",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Backblaze",
      "product": "Backblaze Client",
      "cwe": "CWE-59",
      "title": "Backblaze Client for Windows Improper Link Resolution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19820"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-15101",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpbakery",
      "product": "WPBakery Page Builder",
      "cwe": "CWE-79",
      "title": "WPBakery Page Builder <= 8.7.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15101"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-74837",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.23828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_typescript",
      "cwe": "CWE-770",
      "title": "Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74837"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-77856",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.23828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_typescript",
      "cwe": "CWE-770",
      "title": "Unbounded atom creation from typed struct field names in AshTypescript field selector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77856"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-77950",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.23829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_typescript",
      "cwe": "CWE-209",
      "title": "RPC error handler fails open in AshTypescript, disclosing unredacted errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77950"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-82733",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.23829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_typescript",
      "cwe": "CWE-209",
      "title": "Route handler return value echoed into AshTypescript error response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82733"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-82731",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00288,
      "epss_percentile": 0.20885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_typescript",
      "cwe": "CWE-601",
      "title": "Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82731"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-77189",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.20814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)",
      "cwe": "CWE-89",
      "title": "Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77189"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-82730",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.20648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_typescript",
      "cwe": "CWE-863",
      "title": "Authorization-redacted field values disclosed through AshTypescript result normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82730"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-17589",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "levelfourstorefront",
      "product": "Shopping Cart & eCommerce Store",
      "cwe": "CWE-89",
      "title": "Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL Injection via 'product_order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17589"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-18752",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lukeseager",
      "product": "Persistent Login",
      "cwe": "CWE-89",
      "title": "Persistent Login <= 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wppl_device_id' Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18752"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-19573",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "worschtebrot",
      "product": "Affiliate Super Assistent",
      "cwe": "CWE-79",
      "title": "Affiliate Super Assistent <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19573"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-19796",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webilia",
      "product": "Listdom: AI-powered Business Directory with Classifieds Ads Listings",
      "cwe": "CWE-79",
      "title": "Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 - Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19796"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-13203",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livecomposer",
      "product": "Live Composer – Free WordPress Website Builder",
      "cwe": "CWE-79",
      "title": "Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13203"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-83743",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "invoiceninja",
      "product": "Invoice Ninja",
      "cwe": "CWE-285",
      "title": "invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83743"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-75964",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor",
      "cwe": "CWE-79",
      "title": "User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting via 'email' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75964"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-75980",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot",
      "cwe": "CWE-79",
      "title": "BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75980"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-83744",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "invoiceninja",
      "product": "Invoice Ninja",
      "cwe": "CWE-918",
      "title": "invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83744"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-12747",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.09967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-79",
      "title": "Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12747"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-16787",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livecomposer",
      "product": "Live Composer – Free WordPress Website Builder",
      "cwe": "CWE-79",
      "title": "Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16787"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-75965",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor",
      "cwe": "CWE-79",
      "title": "User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'date' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75965"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-13611",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "KiviCare",
      "cwe": "CWE-200",
      "title": "KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13611"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-48932",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00161,
      "epss_percentile": 0.05574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-444",
      "title": "A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection. Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48932"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-78363",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.04867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MW WP Form",
      "cwe": "CWE-74",
      "title": "MW WP Form < 5.1.5 - Unauthenticated Arbitrary Shortcode Execution via Completion Message Merge Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78363"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-82735",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-400",
      "title": "Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82735"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-82737",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-190",
      "title": "Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82737"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-82738",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-20",
      "title": "Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82738"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-82736",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-180",
      "title": "Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82736"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82734",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.0311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-1284",
      "title": "Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82734"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-82741",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-1287",
      "title": "Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82741"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-82744",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-636",
      "title": "Ash.Reactor change step fails open, skipping a change when its where guard raises",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82744"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-82742",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-400",
      "title": "Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82742"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-82739",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00126,
      "epss_percentile": 0.02598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-209",
      "title": "Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82739"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-82740",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00126,
      "epss_percentile": 0.02599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-20",
      "title": "Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82740"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-82743",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00126,
      "epss_percentile": 0.02599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-400",
      "title": "Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82743"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-18743",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rpm-software-management",
      "product": "popt",
      "cwe": "CWE-131",
      "title": "Popt-devel: popt-static: short realloc in poptconfigfiletostring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18743"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-82745",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-284",
      "title": "ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82745"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-82746",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-862",
      "title": "Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82746"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-82747",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-863",
      "title": "Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82747"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-82749",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-863",
      "title": "Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82749"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-82748",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.02012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-863",
      "title": "Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82748"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-74916",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Fastest Cache",
      "cwe": "CWE-349",
      "title": "WP Fastest Cache 0.8.7.7 - 1.5.0 - Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74916"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-76657",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-287",
      "title": "Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76657"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-76658",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-287",
      "title": "Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76658"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-84147",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Manacle Technologies",
      "product": "Multi-tenant ERP System",
      "cwe": "CWE-434",
      "title": "Remote Code Execution Vulnerability in Manacle Technologies ERP System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84147"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-18210",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company",
      "product": "Products's Store",
      "cwe": "CWE-89",
      "title": "SQL Injection in TRtek Technological Products's Store",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18210"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-18550",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriptsbundle",
      "product": "Nokri – Job Board WordPress Theme",
      "cwe": "CWE-269",
      "title": "Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18550"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-18765",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teracity Software Technologies Inc.",
      "product": "E-OSB",
      "cwe": "CWE-89",
      "title": "SQL Injection in Teracity Sotware's Teracity E-OSB Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18765"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-18808",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Klemsan Electrical Electronics Inc.",
      "product": "KIO (Klemsan Internet Objects)",
      "cwe": "CWE-94",
      "title": "Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18808"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-73749",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73749"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-84372",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "predis",
      "product": "predis",
      "cwe": "CWE-93",
      "title": "Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84372"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-19766",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19766"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-84119",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84119"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-84121",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Sandbox escape due to use-after-free in the DOM: Security component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84121"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-84333",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84333"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-4813",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lutece",
      "product": "Lutece Core",
      "cwe": "CWE-94",
      "title": "Code injection in the Lutece Core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4813"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-84200",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyverno",
      "product": "kyverno",
      "cwe": "CWE-284",
      "title": "Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84200"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2023-54356",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyverno",
      "product": "kyverno",
      "cwe": "CWE-326",
      "title": "Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54356"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2023-54391",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Proxmox Server Solutions GmbH",
      "product": "Proxmox Virtual Environment (VE)",
      "cwe": "CWE-304",
      "title": "Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54391"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-78012",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pyramid Solutions",
      "product": "EtherNet/IP Adapter DLL Kit (EIPA)",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78012"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-84479",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-290",
      "title": "WWBN AVideo Authentication Bypass via User-Agent Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84479"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-84480",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-613",
      "title": "WWBN AVideo Password Recovery Token Expiration Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84480"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-9621",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "RSLinx Classic®",
      "cwe": "CWE-190",
      "title": "RSLinx Classic® - Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9621"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-84148",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Manacle Technologies",
      "product": "Multi-tenant ERP System",
      "cwe": "CWE-639",
      "title": "Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84148"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-84149",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Manacle Technologies",
      "product": "Multi-tenant ERP System",
      "cwe": "CWE-527",
      "title": "Information Disclosure Vulnerability in Manacle Technologies ERP System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84149"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-84189",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-79",
      "title": "LibreNMS before 26.7.0 Stored XSS via Oxidized API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84189"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-18931",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMT Machine Industry and Trade Ltd. Co.",
      "product": "Talassoft Industrial Management Software",
      "cwe": "CWE-798",
      "title": "Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18931"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-51743",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51743"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-73700",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73700"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-73701",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Remote Code Execution in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73701"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-75604",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-22",
      "title": "Next.js: Unauthenticated Remote Code Execution on windows-hosted servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75604"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-79687",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-306",
      "title": "Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79687"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-84324",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84324"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-10195",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fs-code",
      "product": "FS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest]",
      "cwe": "CWE-77",
      "title": "FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10195"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-18630",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMT Machine Industry and Trade Ltd. Co.",
      "product": "Talassoft Industrial Management Software",
      "cwe": "CWE-89",
      "title": "SQL Injection in TMT Machine's Talassoft Industrial Management Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18630"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-58566",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-863",
      "title": "Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58566"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-58567",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-78",
      "title": "Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58567"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-58569",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-829",
      "title": "Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58569"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-58571",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-78",
      "title": "Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58571"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-58572",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-94",
      "title": "Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58572"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-58575",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-290",
      "title": "Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58575"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-72649",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-502",
      "title": "Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72649"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-73702",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Privilege Escalation Vulnerability in the API of HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73702"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-73703",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73703"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-73704",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Command Injection Leading to Administrative Access in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73704"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-73705",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73705"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-73750",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73750"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-73751",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Remote Command Injection in AOS-CX Web-based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73751"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-73752",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73752"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-73753",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73753"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-73782",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73782"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-76111",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-863",
      "title": "Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76111"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-79682",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-77",
      "title": "Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79682"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-79683",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-693",
      "title": "Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79683"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-79684",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-693",
      "title": "Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79684"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-79686",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-693",
      "title": "Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79686"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-84117",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-284",
      "title": "Privilege escalation in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84117"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-84123",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Privilege escalation due to use-after-free in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84123"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-84128",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-284",
      "title": "Privilege escalation in the WebDriver BiDi component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84128"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-84131",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-763",
      "title": "Privilege escalation due to invalid pointer in the Graphics component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84131"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-84187",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-284",
      "title": "AVideo on_publish.php Missing Authentication Check via RTMP Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84187"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-84268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Gvfs: sftp: heap-based buffer overflow in read_reply()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84268"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-84347",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84347"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-84350",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84350"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2024-7952",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "DataEdgePlatform DataMosaix™ Private Cloud",
      "cwe": "CWE-798",
      "title": "DataEdgePlatform DataMosaix™ Private Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-7952"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2024-7953",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "DataEdgePlatform DataMosaix™ Private Cloud",
      "cwe": "CWE-284",
      "title": "DataEdgePlatform DataMosaix™ Private Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-7953"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-9622",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "RSLinx Classic®",
      "cwe": "CWE-191",
      "title": "RSLinx Classic® - Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9622"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-9624",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "RSLinx Classic®",
      "cwe": "CWE-191",
      "title": "RSLinx Classic® - Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9624"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-9625",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "RSLinx Classic®",
      "cwe": "CWE-120",
      "title": "RSLinx Classic® - Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9625"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-9637",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "CompactLogix® 5380 / ControlLogix® 5580",
      "cwe": "CWE-119",
      "title": "CompactLogix® 5380 / ControlLogix® 5580 - Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9637"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-19472",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "ArmorStart® LT",
      "cwe": "CWE-770",
      "title": "Rockwell Automation ArmorStart® LT Denial Of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19472"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-69664",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-772",
      "title": "httpd parks a request worker indefinitely on a malformed chunk size sent after the headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69664"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-70399",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-770",
      "title": "httpd does not enforce the documented default max_clients connection limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70399"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-71380",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-772",
      "title": "httpd applies no timeout while receiving a request body, parking a worker on a stalled client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71380"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-71981",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cypht-org",
      "product": "cypht",
      "cwe": "CWE-502",
      "title": "Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71981"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-74835",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-770",
      "title": "inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74835"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-83605",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-91",
      "title": "xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83605"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-83606",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-400",
      "title": "xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83606"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-83607",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-91",
      "title": "xmldom: Element name injection via createElement() bypasses requireWellFormed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83607"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-83608",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-91",
      "title": "xmldom: DocType `name` Injection Bypasses requireWellFormed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83608"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-83609",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-91",
      "title": "xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83609"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-83612",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-178",
      "title": "xmldom: HTML raw-text closing-tag case mismatch causes output amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83612"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-83613",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-407",
      "title": "xmldom: Quadratic-time attribute deduplication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83613"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-83614",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-400",
      "title": "xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83614"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-83615",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-770",
      "title": "xmldom: Quadratic-memory consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83615"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-83616",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-91",
      "title": "xmldom: Processing Instruction Target Injection Bypasses requireWellFormed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83616"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-83617",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-91",
      "title": "xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83617"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-83618",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-91",
      "title": "xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83618"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-83619",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-400",
      "title": "xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83619"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-84165",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenNebula Systems",
      "product": "OpenNebula",
      "cwe": "CWE-284",
      "title": "Lack of authorisation in OpenNebula by OpenNebula Systems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84165"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-84190",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-77",
      "title": "LibreNMS before 26.5.0 Remote Code Execution via AboutController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84190"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-84202",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelscope",
      "product": "modelscope",
      "cwe": "CWE-502",
      "title": "ModelScope through 1.40.0 Unsafe YAML Deserialization in Model Config Loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84202"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-84208",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-89",
      "title": "AVideo User_Location Plugin Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84208"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-84235",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "1756-ENBT Module",
      "cwe": "CWE-400",
      "title": "Rockwell Automation 1756-ENBT Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84235"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-84304",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grpc",
      "product": "grpc-go",
      "cwe": "CWE-400",
      "title": "gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84304"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-84476",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-290",
      "title": "WWBN AVideo Authentication Bypass via X-Real-IP Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84476"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-84482",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-346",
      "title": "WWBN AVideo Cross-Site Request Forgery via get_domain() validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84482"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2025-12768",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "FactoryTalk® Historian Machine Edition",
      "cwe": "CWE-787",
      "title": "FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12768"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-73706",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized Changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73706"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-84194",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-78",
      "title": "LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84194"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-84203",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usememos",
      "product": "memos",
      "cwe": "CWE-613",
      "title": "Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84203"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-16675",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "FactoryTalk® Activation Manager",
      "cwe": "CWE-307",
      "title": "Rockwell Automation FactoryTalk® Activation Manager - Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16675"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-45221",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EASYBYTE Software",
      "product": "Konga",
      "cwe": "CWE-427",
      "title": "Konga < 2.1.0 Privilege Escalation via Hardcoded OpenSSL Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45221"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-73707",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73707"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-83551",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "sagemaker-python-sdk",
      "cwe": "CWE-312",
      "title": "Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83551"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-73781",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73781"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-63137",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63137"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-66357",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-444",
      "title": "inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66357"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-73276",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-444",
      "title": "inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73276"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-73708",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Fault in Business Logic allows Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73708"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-73709",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation Process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73709"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-73780",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73780"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-73812",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-444",
      "title": "inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73812"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-84195",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyverno",
      "product": "kyverno",
      "cwe": "CWE-200",
      "title": "Kyverno before 1.16.4 Credential Leak via apiCall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84195"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-84196",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyverno",
      "product": "kyverno",
      "cwe": "CWE-918",
      "title": "Kyverno before 1.18.0 Server-Side Request Forgery via apiCall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84196"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-84335",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84335"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-84351",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-121",
      "title": "Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84351"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2024-10085",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "EcoStruxure™ OPC UA Server Expert",
      "cwe": "CWE-770",
      "title": "CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-10085"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-18730",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-918",
      "title": "Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18730"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-55951",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-770",
      "title": "httpc memory exhaustion via unbounded response header accumulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55951"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-66835",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-50",
      "title": "httpd mod_auth directory protection bypassed by a doubled slash in the request path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66835"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-73270",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-178",
      "title": "httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73270"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-73710",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73710"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-73779",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73779"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-75538",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-122",
      "title": "A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75538"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-84370",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svg",
      "product": "svgo",
      "cwe": "CWE-79",
      "title": "SVGO: removeScripts allows executable links through namespace and control-character bypasses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84370"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-19513",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gravity Forms",
      "product": "Gravity Forms",
      "cwe": "CWE-434",
      "title": "Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19513"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-73711",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Privilege Escalation allows Administrative Access in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73711"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-73712",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73712"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-73777",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73777"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-73778",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Credential Manager Vulnerability Allows Unauthorized Administrative Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73778"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-84218",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-184",
      "title": "Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84218"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-84334",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84334"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-73776",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73776"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-61750",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61750"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-61751",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61751"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-61752",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61752"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-61753",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-22",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61753"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-61754",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61754"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-61755",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61755"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-61756",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61756"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-61757",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61757"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-61758",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61758"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-61759",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61759"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-61760",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61760"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-61761",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61761"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-61762",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61762"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-61763",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61763"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-61764",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61764"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-61765",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61765"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-61766",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61766"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-61767",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61767"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-61768",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61768"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-61769",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61769"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-61770",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61770"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-61771",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61771"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-61772",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61772"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-61773",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61773"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-61774",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61774"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-61775",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61775"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-61776",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61776"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-61777",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61777"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-61778",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61778"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-61779",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61779"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-73713",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Local Privilege Escalation Vulnerabilities in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73713"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-83549",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "SMA1000",
      "cwe": "CWE-78",
      "title": "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83549"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-19118",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-367",
      "title": "Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19118"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-73775",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73775"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-76851",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76851"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-84361",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "composer",
      "product": "composer",
      "cwe": "CWE-78",
      "title": "Composer: Perforce source URL permits P4PORT `rsh:` command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84361"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-73714",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73714"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-73774",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73774"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-18771",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMT Machine Industry and Trade Ltd. Co.",
      "product": "Talassoft Industrial Management Software",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in TMT Machine's Talassoft Industrial Management Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18771"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-49329",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-407",
      "title": "Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49329"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-51766",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51766"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-52130",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-674",
      "title": "llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52130"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-73715",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73715"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-73716",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Remote Code Execution in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73716"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-73717",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73717"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-73771",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Improper Authentication Handling in AOS-CX Management Interface and API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73771"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-73773",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73773"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-84145",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84145"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-84374",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpartnerNL",
      "product": "Laravel-Excel",
      "cwe": "CWE-22",
      "title": "Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84374"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-84375",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodeca",
      "product": "js-yaml",
      "cwe": "CWE-400",
      "title": "js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84375"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-73718",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Information Disclosure in Web Interface allows Sensitive Data Exposure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73718"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-84366",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scrapy",
      "product": "scrapy",
      "cwe": "CWE-319",
      "title": "Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84366"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-13336",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "NetBotz 5 - 750/755",
      "cwe": "CWE-78",
      "title": "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13336"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-73768",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Local Privilege Escalation in AOS-CX Command Line Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73768"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-73770",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Arbitrary File Write Vulnerability Leading to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73770"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-78592",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78592"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2024-14047",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elastic Security",
      "cwe": "CWE-59",
      "title": "Improper Link Resolution Before File Access ('Link Following') in Winlogbeat Leading to Arbitrary File Write and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14047"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-73719",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73719"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-73720",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Insecure File Handling allows Remote Code Execution in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73720"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-73721",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated SQL Injection Vulnerabilities in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73721"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-73722",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Command Injection Vulnerabilities in HPE Networking Fabric Composer Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73722"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-73765",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73765"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-73766",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Command Injection Vulnerabilities in the API Endpoint of AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73766"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-73767",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73767"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-83595",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "AVideo Cross-Site Request Forgery via plugin/API/set.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83595"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-18780",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMT Machine Industry and Trade Ltd. Co.",
      "product": "Talassoft Industrial Management Software",
      "cwe": "CWE-352",
      "title": "CSRF in TMT Machine's Talassoft Industrial Management Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18780"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-73723",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Privilege Escalation Leading to Unauthorized State Changes in HPE Networking Fabric Composer Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73723"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-73724",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73724"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-73763",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Remote Command Execution in Management Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73763"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-73764",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73764"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-84192",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-79",
      "title": "LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84192"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-84204",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "growilabs",
      "product": "growi",
      "cwe": "CWE-862",
      "title": "GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84204"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-84205",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "growilabs",
      "product": "growi",
      "cwe": "CWE-639",
      "title": "GROWI through 8.0.2 Authorization Bypass Through User-Controlled Key on apiv3 Revision Retrieval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84205"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-9633",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "Redundancy Module Configuration Tool",
      "cwe": "CWE-276",
      "title": "Redundancy Module Configuration Tool - Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9633"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-9634",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "Redundancy Module Configuration Tool",
      "cwe": "CWE-276",
      "title": "Redundancy Module Configuration Tool - Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9634"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-12663",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "ControlFLASH ®",
      "cwe": "CWE-306",
      "title": "ControlFLASH ® – Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12663"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-73725",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Local Privilege Escalation leads to Arbitrary Code Execution in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73725"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-84233",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84233"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2025-15613",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyverno",
      "product": "kyverno",
      "cwe": "CWE-918",
      "title": "Kyverno before v1.13.4 SSRF via Service Call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15613"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-8712",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OHF-Voice",
      "product": "wyoming",
      "cwe": "CWE-918",
      "title": "Wyoming < 1.10.2 SSRF via uri Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8712"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-13348",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "PowerChute™ Serial Shutdown",
      "cwe": "CWE-307",
      "title": "CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13348"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-19471",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "ArmorStart® LT",
      "cwe": "CWE-79",
      "title": "Rockwell Automation ArmorStart® LT Stored Cross-site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19471"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-59696",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-1284",
      "title": "uri_string does not bound the port component of a URI before integer conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59696"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-83611",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-1286",
      "title": "xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83611"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-84199",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyverno",
      "product": "kyverno",
      "cwe": "CWE-918",
      "title": "Kyverno before 1.16.2 SSRF via APICall Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84199"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-84201",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argneshu",
      "product": "appium-mcp-server",
      "cwe": "CWE-22",
      "title": "appium-mcp-server through 0.1.61 Path Traversal in write_file and write_files_batch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84201"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-84309",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-835",
      "title": "pypdf: Possible infinite loop for TreeObject.insert_child",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84309"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-84478",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-73",
      "title": "WWBN AVideo Unauthenticated Arbitrary Log File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84478"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-84481",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo through 30.0 Information Disclosure via MobileManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84481"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-84483",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-321",
      "title": "WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84483"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-73726",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73726"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-73762",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73762"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-11873",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 9",
      "cwe": "CWE-209",
      "title": "Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11873"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-33465",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33465"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-63138",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-943",
      "title": "Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63138"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-72628",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-409",
      "title": "Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72628"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-72644",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-248",
      "title": "Uncaught Exception in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72644"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-72652",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72652"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-72654",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-250",
      "title": "Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72654"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-72682",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72682"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-73727",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73727"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-73728",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Denial of Service Vulnerabilities in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73728"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-73729",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73729"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-73730",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73730"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-73758",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73758"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-73759",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73759"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-73760",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73760"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-73761",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73761"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-73772",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73772"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-78608",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78608"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-79685",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore 500T",
      "cwe": "CWE-88",
      "title": "Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79685"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-84269",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Gvfs: afp: heap-based buffer overflow in dsi read path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84269"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-84306",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-294",
      "title": "Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84306"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-84327",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84327"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-84348",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84348"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-84365",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-22",
      "title": "Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84365"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-7877",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bootstrapped Ventures",
      "product": "WP Recipe Maker Premium",
      "cwe": "CWE-79",
      "title": "WP Recipe Maker Premium <= 10.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wprm-call-to-action' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7877"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-73757",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73757"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-84470",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-862",
      "title": "Automation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84470"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-70405",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-1284",
      "title": "snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70405"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-70409",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-1284",
      "title": "eldap does not bound the port component of a referral URL before integer conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70409"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-71562",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-1284",
      "title": "httpc does not bound server-supplied numeric header values before integer conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71562"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-83610",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xmldom",
      "product": "xmldom",
      "cwe": "CWE-116",
      "title": "xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83610"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-84303",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grpc",
      "product": "grpc-go",
      "cwe": "CWE-178",
      "title": "gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84303"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-84308",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpseclib",
      "product": "phpseclib",
      "cwe": "CWE-208",
      "title": "phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84308"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-73731",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73731"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-84369",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svg",
      "product": "svgo",
      "cwe": "CWE-79",
      "title": "SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84369"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-74994",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-863",
      "title": "inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74994"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-51742",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51742"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-51748",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51748"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-51756",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51756"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-73756",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73756"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-78605",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-444",
      "title": "Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78605"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-84363",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-444",
      "title": "Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84363"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-84373",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vitest-dev",
      "product": "vitest",
      "cwe": "CWE-22",
      "title": "Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84373"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-84193",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-79",
      "title": "LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84193"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-73755",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Privilege Escalation via Unauthorized Access to Sensitive Session Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73755"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-73732",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-200",
      "title": "Local Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73732"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-83557",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-502",
      "title": "jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83557"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-10420",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "mTower",
      "cwe": "CWE-822",
      "title": "Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10420"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-82926",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "mTower",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82926"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-82927",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "mTower",
      "cwe": "CWE-822",
      "title": "Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82927"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-84110",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Releasit",
      "product": "Releasit COD Form & Upsells",
      "cwe": "CWE-602",
      "title": "Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84110"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-84111",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chanjet",
      "product": "CRM",
      "cwe": "CWE-74",
      "title": "Chanjet CRM jxf_dump_table.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84111"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-84115",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cleo",
      "product": "Harmony",
      "cwe": "CWE-266",
      "title": "Cleo Harmony JWT Refresh Token connections privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84115"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-84423",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Casdoor",
      "cwe": "CWE-287",
      "title": "Casdoor upload-resource API resource.go missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84423"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-72641",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72641"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-73733",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-287",
      "title": "Authentication Bypasses in API allow Continued Authenticated Access in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73733"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-73734",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-601",
      "title": "Unauthenticated Open Redirect allows URL Manipulation in HPE Networking Fabric Composer Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73734"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-73735",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-552",
      "title": "Authenticated Access Control Vulnerabilities allow Information Disclosure in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73735"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-78607",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Elasticsearch Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78607"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-84118",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the JavaScript: GC component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84118"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-84120",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Audio/Video component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84120"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-84122",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Audio/Video component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84122"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-84124",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84124"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-84125",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84125"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-84232",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-79",
      "title": "Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84232"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-84371",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-79",
      "title": "ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84371"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-51745",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51745"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-51752",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51752"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-51761",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51761"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-53682",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 9",
      "cwe": "CWE-200",
      "title": "Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53682"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-63435",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mikel",
      "product": "mail",
      "cwe": "CWE-436",
      "title": "Mail: Email address spoofing via malformed RFC 2047 encoded-words",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63435"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-73736",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-552",
      "title": "Unauthenticated Limited Information Disclosure leads to Data Exposure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73736"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-73754",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73754"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-77194",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpinsider-1",
      "product": "Simple Membership",
      "cwe": "CWE-287",
      "title": "Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77194"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-84061",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhongyu09",
      "product": "OpenChatBI",
      "cwe": "CWE-74",
      "title": "zhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84061"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-84191",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-79",
      "title": "LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84191"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-84206",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84206"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-84207",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heymrun",
      "product": "heym",
      "cwe": "CWE-918",
      "title": "Heym before 0.0.98 SSRF via WebSocket endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84207"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-84323",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84323"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-84329",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-441",
      "title": "Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84329"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-84364",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-400",
      "title": "Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84364"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-13337",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "NetBotz 5 - 750/755",
      "cwe": "CWE-564",
      "title": "CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13337"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-73524",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cypht-org",
      "product": "cypht",
      "cwe": "CWE-79",
      "title": "Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73524"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-84305",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andialbrecht",
      "product": "sqlparse",
      "cwe": "CWE-407",
      "title": "sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84305"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-84477",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo Stored XSS via Live Schedule Title Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84477"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-56143",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56143"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-73783",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "AOS-CX",
      "cwe": null,
      "title": "Authenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73783"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-12661",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "FactoryTalk® Historian Machine Edition",
      "cwe": "CWE-121",
      "title": "FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12661"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-73737",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-22",
      "title": "Unauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73737"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-84188",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-79",
      "title": "librenms before 26.7.0 Stored XSS via graph_descr settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84188"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-84310",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-405",
      "title": "pypdf: Possible long runtimes/large memory usage when retrieving outlines",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84310"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-84311",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-834",
      "title": "pypdf: Possible long runtimes/large memory usage when extracting XForm objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84311"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-73738",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-200",
      "title": "Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73738"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-73739",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-200",
      "title": "Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73739"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-73740",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-269",
      "title": "Local Privilege Escalation in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73740"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-72633",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72633"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-73741",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-284",
      "title": "Authenticated Limited File Read allows Data Exposure in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73741"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-73742",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-290",
      "title": "Improper Client Address Validation allows Request Attribution Spoofing in Fabric Composer API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73742"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-78597",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78597"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-78603",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78603"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-84126",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-120",
      "title": "Incorrect boundary conditions in the Layout: Grid component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84126"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-84127",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the WebExtensions component in Firefox for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84127"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-84267",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-908",
      "title": "Gvfs: sftp: uninitialized heap disclosure in read_string()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84267"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-84270",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gvfs: mtp: out-of-bounds read in do_read()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84270"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-78606",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78606"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-73743",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-319",
      "title": "Unauthenticated Information Disclosure Leading to Data Exposure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73743"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-84307",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-204",
      "title": "Filament: Password validity disclosure for accounts denied panel access on login page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84307"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-84367",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "joi",
      "cwe": "CWE-1321",
      "title": "joi: object().rename() with a template target can set the validated object's prototype",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84367"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-84368",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "joi",
      "cwe": "CWE-1321",
      "title": "joi: Prototype pollution via a `__proto__` language key in custom messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84368"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-73744",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-400",
      "title": "Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73744"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-81846",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "runZero",
      "product": "Platform",
      "cwe": "CWE-639",
      "title": "runZero MCP 'Findings summaries' Data Leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81846"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-73745",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": null,
      "title": "Unauthenticated Limited Information Disclosure allows Data Exposure in the API of HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73745"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-73746",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-400",
      "title": "Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73746"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-73747",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-269",
      "title": "Local Privilege Escalation Vulnerability in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73747"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-73748",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "Fabric Composer",
      "cwe": "CWE-312",
      "title": "Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73748"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-84059",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ICP DAS",
      "product": "UA-2200",
      "cwe": "CWE-74",
      "title": "ICP DAS UA-2200/UA-5200 CGI ArmAngstromInstructionSet command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84059"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-84109",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xinhu",
      "product": "Rainrock RockOA",
      "cwe": "CWE-74",
      "title": "Xinhu Rainrock RockOA webmainAction.php getOrder sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84109"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-84114",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cleo",
      "product": "Harmony",
      "cwe": "CWE-287",
      "title": "Cleo Harmony SAML Authentication LocalUserUtil.getNativeUserByAssertions improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84114"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-84153",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xinhu",
      "product": "Rainrock RockOA",
      "cwe": "CWE-74",
      "title": "Xinhu Rainrock RockOA index.php toaddval sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84153"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-84287",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-404",
      "title": "NousResearch hermes-agent Session Chat api_server.py denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84287"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-84288",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-404",
      "title": "NousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.prompt denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84288"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-84289",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-400",
      "title": "NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84289"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-19590",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenAI",
      "product": "Codex Desktop",
      "cwe": "CWE-427",
      "title": "OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19590"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-19591",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenAI",
      "product": "Codex CLI",
      "cwe": "CWE-150",
      "title": "OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting user approval. On macOS and Linux, exploitation additionally requires separately installed PowerShell Core (pwsh) to be invoked. If filesystem protections permit the write, the command can modify Codex's configuration. If Codex later loads the modified configuration, it can launch an attacker-controlled MCP server and execute code with the user's privileges, allowing it to read, change, or delete files accessible to that account. The approval bypass does not disable filesystem sandboxing; the default filesystem sandbox on macOS and Linux can prevent writes outside permitted locations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19591"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-19592",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenAI",
      "product": "Codex CLI",
      "cwe": "CWE-15",
      "title": "OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an attacker-controlled filesystem-monitor helper, Git can execute that helper while Codex collects repository metadata. The helper runs outside Codex's command sandbox and without a user-approval prompt, allowing attacker-controlled code to run with the user's privileges. The code can read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the source repository's local .git/config; exploitation requires a repository delivered or copied with that configuration intact.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19592"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-19593",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenAI",
      "product": "Codex Desktop",
      "cwe": "CWE-15",
      "title": "OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19593"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-51741",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51741"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-51744",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51744"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-51747",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51747"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-51750",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51750"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-51751",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51751"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-51754",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51754"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-51757",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51757"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-51760",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51760"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-51762",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51762"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-51763",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51763"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-51764",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51764"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-51765",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51765"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-51767",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51767"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-51768",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51768"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-51769",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51769"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-51770",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51770"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-51788",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51788"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-51934",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdlineRun function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51934"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-51956",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51956"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-51974",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via a crafted styles payload in the EXIF metadata of an uploaded image file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51974"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-52022",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52022"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-52023",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52023"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-52111",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52111"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-52131",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52131"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-52132",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52132"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-52295",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52295"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-80047",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hugging Face",
      "product": "Transformers",
      "cwe": null,
      "title": "Hugging Face Transformers library writes remote code to disk prior to consent check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80047"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-81928",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-DNS",
      "cwe": "CWE-674",
      "title": "Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81928"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-83548",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "SMA1000",
      "cwe": "CWE-441",
      "title": "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83548"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-84129",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84129"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-84130",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Information disclosure in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84130"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-84132",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Information disclosure in the Networking: HTTP component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84132"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-84133",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the DOM: Push Subscriptions component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84133"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-84134",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Other issue in the Profile Backup component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84134"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-84135",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Other issue in Firefox Focus for Android",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84135"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-84136",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Other issue in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84136"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-84137",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Spoofing issue in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84137"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-84138",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Denial-of-service in the PDF Viewer component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84138"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-84139",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Clickjacking issue in the DOM: Events component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84139"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-84140",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Site isolation issue in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84140"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-84141",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Integer overflow in the Graphics: ImageLib component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84141"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-84142",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Internally found bugs fixed in Thunderbird 155",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84142"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-84143",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84143"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-84144",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": null,
      "title": "Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84144"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-84325",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84325"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-84326",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-908",
      "title": "Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84326"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-84328",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84328"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-84330",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84330"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-84331",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84331"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-84332",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84332"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-84349",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84349"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-84352",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84352"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-84353",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84353"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-84354",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84354"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-84355",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84355"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-84356",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84356"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-84357",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84357"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-84358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84358"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-84359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84359"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-84637",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": null,
      "title": "Calendar invitation attachments could launch local executables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84637"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-84639",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": null,
      "title": "Uninitialized memory in MIME parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84639"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-84640",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": null,
      "title": "One byte overflow read in mail parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84640"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-84641",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": null,
      "title": "Information disclosure due to malicious IMAP server response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84641"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-84642",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": null,
      "title": "Allowed UNC hostnames for attachments interpreted as a regular expression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84642"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-39533",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-39533 (libp2p go-libp2p). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-6387",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-6387 (OpenSSH). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-4598",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-5914",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-6021",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0989",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0989 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0990",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0990 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-0992",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-0992 (Red Hat Hardened Images). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10659",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10659 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10683",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10683 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10685",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10685 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10773",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10773 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10774 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10848",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10848 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10849 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11368",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11368 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19694",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19694 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19695",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19695 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19696",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19696 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2411 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26899. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29786",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29786 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33939 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33940",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33940 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33941",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33941 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3832",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39931",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39931 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39932",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39932 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43500",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43500 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53622",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53622 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5704",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62911",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62911 (Microsoft Exchange Server 2016 Cumulative Update 23). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67307",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67307 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67312",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67312 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67313",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67313 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67314",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67314 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67315",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67315 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67316",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67316 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67317",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67317 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67318",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67318 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67319",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67319 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67320",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67320 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67321",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67321 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67611",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67611 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7007 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74883",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74883 (jahlives openssl_encrypt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75918",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75918 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75919",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75919 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75920",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75920 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76205",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76205 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76208",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76208 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76209",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76209 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76210",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76210 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76211",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76211 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76212",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76212 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76213",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76213 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76215",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76215 (thorsten phpMyFAQ). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76879",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76879 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76881 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76924",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76924 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76926",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76926 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78465",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78465 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78681",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78681 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79675",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79675 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79720",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79720 (Netron). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80205",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80205 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80206",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80206 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81725",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81725 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82482",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82482 (coppermine-gallery Coppermine Photo Gallery). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82487 (Beetel 450TC3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82539",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82539 (TOTOLINK A720R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82542",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82542 (Tenda HG10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82548",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82548 (Linux Foundation Magma). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82553",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82553 (sambitraj Student Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82593",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82593 (D-Link DIR-825M). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82598",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82598 (SeaCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82603",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82603 (SeaCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82609",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82609 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82614",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82614 (itsourcecode Online Medicine Delivery System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82616",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82616 (TOTOLINK NR1800X). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82620 (Soarkey StudentManagement). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82625 (code-projects Simple Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82664",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82664 (yaojingang GEOFlow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82688",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82688 (D-Link DNS-340L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82807",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82807 (ieungSoft Ultra RAMDisk Pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82820",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82820 (FLVMeta). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82833 (Doccano Open Source Annotation Tools for Machine Learning Practitioners). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82835",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82835 (caoqianming django-vue-admin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82906",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82906 (sdcb chats). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82908",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82908 (MSI Dragon Center). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82914",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82914 (kishan0725 Hospital-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82921",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82921 (ShopEx ECShop). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82922 (ShopEx ECShop). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82971",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82971 (QVidium Opera11). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-83524",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-83524 (RedPort Optimizer wXa-203). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19694",
      "detail": "RESCORED — CVE-2026-19694 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19695",
      "detail": "RESCORED — CVE-2026-19695 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19696",
      "detail": "RESCORED — CVE-2026-19696 (Wireshark Foundation Wireshark). CVSS 6.6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33941",
      "detail": "RESCORED — CVE-2026-33941 (handlebars-lang handlebars.js). CVSS 8.3 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-34714",
      "detail": "RESCORED — CVE-2026-34714 (Vim). CVSS 9.2 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47863",
      "detail": "RESCORED — CVE-2026-47863 (Spring Reactor Core). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47881",
      "detail": "RESCORED — CVE-2026-47881 (Spring Batch). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47894",
      "detail": "RESCORED — CVE-2026-47894 (Spring Cloud Config). CVSS 4.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-5704",
      "detail": "RESCORED — CVE-2026-5704 (Red Hat Enterprise Linux 10). CVSS 5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59270",
      "detail": "RESCORED — CVE-2026-59270 (Spring Security). CVSS 9.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59271",
      "detail": "RESCORED — CVE-2026-59271 (Spring AMQP). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59275",
      "detail": "RESCORED — CVE-2026-59275 (Spring AMQP). CVSS 6.6 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59354",
      "detail": "RESCORED — CVE-2026-59354 (VMware by Broadcom Spring Security (OAuth2 Authorization Server module)). CVSS 9.6 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65081",
      "detail": "RESCORED — CVE-2026-65081 (NVIDIA NemoClaw). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65082",
      "detail": "RESCORED — CVE-2026-65082 (NVIDIA NemoClaw). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65084",
      "detail": "RESCORED — CVE-2026-65084 (NVIDIA NemoClaw). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65087",
      "detail": "RESCORED — CVE-2026-65087 (NVIDIA NemoClaw). CVSS 5.6 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65097",
      "detail": "RESCORED — CVE-2026-65097 (NVIDIA NemoClaw). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65098",
      "detail": "RESCORED — CVE-2026-65098 (NVIDIA NemoClaw). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66780",
      "detail": "RESCORED — CVE-2026-66780 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 9.9 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66781",
      "detail": "RESCORED — CVE-2026-66781 (Red Hat Advanced Cluster Management for Kubernetes 2.11). CVSS 6.5 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66782",
      "detail": "RESCORED — CVE-2026-66782 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 7.8 → 5.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66783",
      "detail": "RESCORED — CVE-2026-66783 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 8.2 → 4.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66785",
      "detail": "RESCORED — CVE-2026-66785 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 9.9 → 2.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66787",
      "detail": "RESCORED — CVE-2026-66787 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 8.7 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66788",
      "detail": "RESCORED — CVE-2026-66788 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 9.9 → 3.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66795",
      "detail": "RESCORED — CVE-2026-66795 (Red Hat multicluster engine for Kubernetes 2.10). CVSS 9.1 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-6876",
      "detail": "RESCORED — CVE-2026-6876 (ServiceNow AI Platform). CVSS 8.7 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75052",
      "detail": "RESCORED — CVE-2026-75052 (JetBrains IntelliJ IDEA). CVSS 3.6 → 4.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75871",
      "detail": "RESCORED — CVE-2026-75871 (GitLab AI Gateway). CVSS 8.2 → 9.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76881",
      "detail": "RESCORED — CVE-2026-76881 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76926",
      "detail": "RESCORED — CVE-2026-76926 (Wireshark Foundation Wireshark). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79938",
      "detail": "RESCORED — CVE-2026-79938 (Dell Power Protect Cyber Recovery). CVSS 7.6 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79939",
      "detail": "RESCORED — CVE-2026-79939 (Dell Power Protect Cyber Recovery). CVSS 5.8 → 7.8 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2024-58377",
      "detail": "REJECTED — CVE-2024-58377 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2024-58378",
      "detail": "REJECTED — CVE-2024-58378 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2025-71346",
      "detail": "REJECTED — CVE-2025-71346 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2025-71406",
      "detail": "REJECTED — CVE-2025-71406 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2025-71407",
      "detail": "REJECTED — CVE-2025-71407 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78477",
      "detail": "REJECTED — CVE-2026-78477 (MVPThemes Jawn). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78562",
      "detail": "REJECTED — CVE-2026-78562 (Mikado-Themes Verdure Core). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78563",
      "detail": "REJECTED — CVE-2026-78563 (WPDeveloper NotificationX Pro). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78566",
      "detail": "REJECTED — CVE-2026-78566 (Edge-Themes Shuffle). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78568",
      "detail": "REJECTED — CVE-2026-78568 (KlbTheme Total Donations). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78570",
      "detail": "REJECTED — CVE-2026-78570 (KlbTheme Total Donations). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78572",
      "detail": "REJECTED — CVE-2026-78572 (unknown Kalles Addons). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-78576",
      "detail": "REJECTED — CVE-2026-78576 (Readabler). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-28191",
      "detail": "PATCH SHIPPED — CVE-2026-28191 (ThemeOne The Grid). Fixed in The Grid 2.8.1."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
