{
  "day": "2026-09-02",
  "boundary": "UTC calendar day",
  "published_count": 322,
  "by_severity": {
    "CRITICAL": 23,
    "HIGH": 113,
    "MEDIUM": 155,
    "LOW": 25
  },
  "kev_count": 0,
  "exploit_reference_count": 4,
  "awaiting_enrichment_count": 6,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-14828",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01443,
      "epss_percentile": 0.71415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Password Manager Pro",
      "cwe": "CWE-89",
      "title": "Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14828"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-78657",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00718,
      "epss_percentile": 0.51399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "SigmaForms Pro – AI Generated Forms",
      "cwe": "CWE-22",
      "title": "SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78657"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2025-46418",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00676,
      "epss_percentile": 0.49785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Westermo",
      "product": "WeOS",
      "cwe": "CWE-78",
      "title": "Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46418"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-14357",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00646,
      "epss_percentile": 0.48537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dplugins",
      "product": "DevKit Pro",
      "cwe": "CWE-862",
      "title": "DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14357"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-14957",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00555,
      "epss_percentile": 0.44164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Libreswan Project",
      "product": "libreswan",
      "cwe": "CWE-252",
      "title": "FIPS mode assertion failure via malicious CERT payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14957"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-14982",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00518,
      "epss_percentile": 0.42045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JoomUnited",
      "product": "WP File Download",
      "cwe": "CWE-22",
      "title": "WP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14982"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-84484",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00477,
      "epss_percentile": 0.3939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nasa-jpl",
      "product": "ION-DTN",
      "cwe": "CWE-125",
      "title": "ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnv",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84484"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-84694",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify before 4.2.0 Remote Code Execution via Environment Variable Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84694"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-84441",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Piwigo",
      "cwe": "CWE-22",
      "title": "Piwigo Image Derivative i.php path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84441"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-84175",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.32766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Ditto",
      "cwe": "CWE-674",
      "title": "In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirects without re-validating the redirect target and without a hop limit. An authenticated user who is permitted to create a Thing, or who holds WRITE permission on an existing Thing, can thereby cause the Things service to issue arbitrary HTTP GET requests from inside the deployment's network — including to cloud instance-metadata endpoints and other internal services — and can use the differing error responses returned to the caller to enumerate internal services. Versions 2.4.0 to 2.5.x contain the same code, but are only affected where the operator explicitly enabled the WoT integration feature toggle, which is disabled by default in those versions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84175"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-19116",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Frontend",
      "cwe": "CWE-502",
      "title": "WP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19116"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-84702",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facefusion",
      "product": "facefusion",
      "cwe": "CWE-22",
      "title": "facefusion before 3.7.0 Path Traversal via Job Identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84702"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-84699",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.29653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Team Password Manager",
      "product": "Team Password Manager",
      "cwe": "CWE-640",
      "title": "Team Password Manager before 14.184.308 Authentication Bypass in Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84699"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-84700",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenAtomFoundation",
      "product": "pikiwidb",
      "cwe": "CWE-306",
      "title": "Pika Unauthenticated Replication Access via Internal Protobuf Port",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84700"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-84485",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apitable",
      "product": "apitable",
      "cwe": "CWE-306",
      "title": "APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84485"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-84715",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MythicalLTD",
      "product": "FeatherPanel",
      "cwe": "CWE-862",
      "title": "FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84715"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-75528",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.22594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Broken Link Checker",
      "cwe": "CWE-79",
      "title": "Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75528"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-9055",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.2124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "melograno",
      "product": "Booking for Appointments and Events Calendar – Amelia",
      "cwe": "CWE-269",
      "title": "Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9055"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-19754",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Baserow",
      "product": "Baserow",
      "cwe": "CWE-89",
      "title": "Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19754"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2024-35585",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oxford Nanopore",
      "product": "MinKNOW",
      "cwe": "CWE-306",
      "title": "Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-35585"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-84698",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PX4",
      "product": "PX4-Autopilot",
      "cwe": "CWE-787",
      "title": "PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84698"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-84425",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.18949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "CowAgent",
      "cwe": "CWE-404",
      "title": "zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84425"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-84427",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.18949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "CowAgent",
      "cwe": "CWE-404",
      "title": "zhayujie CowAgent Bash Tool bash.py denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84427"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-84695",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.16914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bookstackapp",
      "product": "bookstack",
      "cwe": "CWE-79",
      "title": "BookStack before 26.05.4 Stored XSS via Drawing Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84695"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-84430",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.15814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "gouguoa",
      "cwe": "CWE-913",
      "title": "gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84430"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-84697",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-918",
      "title": "Mailpit SSRF Deny List Bypass via Azure Metadata and IPv6 Prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84697"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2025-7963",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tymotey",
      "product": "Easy Waveform Player",
      "cwe": "CWE-79",
      "title": "Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_easywaveformplayer Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7963"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-84437",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.08799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenCart",
      "cwe": "CWE-79",
      "title": "OpenCart Autocomplete Workflow address.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84437"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-84438",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.08798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenCart",
      "cwe": "CWE-79",
      "title": "OpenCart Autocomplete Workflow edit.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84438"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-14215",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-862",
      "title": "Amelia < 2.4.9 - Unauthenticated Post-Booking Action Trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14215"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-19704",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Comments",
      "cwe": "CWE-89",
      "title": "Comments – wpDiscuz < 7.6.66 - Unauthenticated Comment Disclosure via SQLi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19704"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-12865",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Photo Gallery by 10Web",
      "cwe": "CWE-79",
      "title": "Photo Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12865"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-82968",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-639",
      "title": "Keycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82968"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-3851",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.06833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elegant Themes",
      "product": "Divi",
      "cwe": "CWE-79",
      "title": "Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3851"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-81807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Ajax Chat",
      "cwe": "CWE-79",
      "title": "Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81807"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-77792",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RegistrationMagic",
      "cwe": "CWE-79",
      "title": "RegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77792"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-84701",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocobase",
      "product": "nocobase",
      "cwe": "CWE-79",
      "title": "NocoBase Rich Text Field Stored Cross-Site Scripting via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84701"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-53683",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": null,
      "title": "Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53683"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-84431",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AirAsia",
      "product": "MOVE App",
      "cwe": "CWE-22",
      "title": "AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84431"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-84442",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MapQuest",
      "product": "Get Directions App",
      "cwe": "CWE-22",
      "title": "MapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt getDataColumn path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84442"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-19719",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.05862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Social Media Share Buttons & Social Sharing Icons",
      "cwe": "CWE-79",
      "title": "Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stored XSS via Post Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19719"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-19723",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Social Media Share Buttons & Social Sharing Icons",
      "cwe": "CWE-79",
      "title": "Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via Pin It Share Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19723"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2025-15663",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Before After Image Slider & Gallery",
      "cwe": "CWE-79",
      "title": "BEAF < 4.7.19 - Author+ Stored XSS via After Label",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15663"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2025-15664",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Before After Image Slider & Gallery",
      "cwe": "CWE-79",
      "title": "BEAF < 4.7.19 - Author+ Stored XSS via Before Label",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15664"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-3850",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elegant Themes",
      "product": "Divi",
      "cwe": "CWE-79",
      "title": "Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3850"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-81737",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FAQ Builder AYS",
      "cwe": "CWE-79",
      "title": "FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81737"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-77782",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rank Math SEO",
      "cwe": "CWE-200",
      "title": "Rank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77782"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-82182",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPvivid — Backup, Migration & Staging",
      "cwe": "CWE-89",
      "title": "WPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82182"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-84696",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00149,
      "epss_percentile": 0.04404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phison Electronics Corporation",
      "product": "PS3111-S11 Controller Firmware",
      "cwe": "CWE-306",
      "title": "Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84696"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82183",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "OAuth Single Sign On",
      "cwe": "CWE-287",
      "title": "OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID Assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82183"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-82883",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Marcus",
      "product": "Login With Ajax",
      "cwe": "CWE-79",
      "title": "WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82883"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-16966",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Solace Extra",
      "cwe": "CWE-200",
      "title": "Solace Extra < 1.7.0 - Unauthenticated Draft/Private Site Builder Content Disclosure via get_elementor_content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16966"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-19251",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Member",
      "cwe": "CWE-200",
      "title": "Ultimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via Profile Activity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19251"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-16983",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Gutentor",
      "cwe": "CWE-200",
      "title": "Gutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16983"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-15232",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MotoPress Appointment Booking",
      "cwe": "CWE-639",
      "title": "Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15232"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-74927",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MultiVendorX",
      "cwe": "CWE-862",
      "title": "MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74927"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-12526",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Advanced Custom Fields: Extended",
      "cwe": "CWE-287",
      "title": "Advanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Account Takeover via Front-End User Update Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12526"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-78151",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FormLayer",
      "cwe": "CWE-200",
      "title": "FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78151"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-81195",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-200",
      "title": "MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81195"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-81197",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-200",
      "title": "MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81197"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-19453",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.0378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetBackup",
      "cwe": "CWE-269",
      "title": "JetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore Admin User Selection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19453"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-77764",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GamiPress",
      "cwe": "CWE-639",
      "title": "GamiPress < 7.9.9.6 - Subscriber+ Arbitrary User Points and Achievement Award via Watch-Video Listeners",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77764"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-77783",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.0378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rank Math SEO",
      "cwe": "CWE-639",
      "title": "Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77783"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-77784",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.0378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rank Math SEO",
      "cwe": "CWE-639",
      "title": "Rank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77784"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-81583",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Theme My Login",
      "cwe": "CWE-269",
      "title": "Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81583"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-80467",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Advanced Custom Fields: Extended",
      "cwe": "CWE-269",
      "title": "Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80467"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-81428",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WC Vendors",
      "cwe": "CWE-639",
      "title": "WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81428"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-77788",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rank Math SEO",
      "cwe": "CWE-639",
      "title": "Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77788"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-81194",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81194"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-81427",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WC Vendors",
      "cwe": "CWE-862",
      "title": "WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81427"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-81198",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81198"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-77785",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rank Math SEO",
      "cwe": "CWE-639",
      "title": "Rank Math SEO < 1.0.277 - Author+ Non-Public Post Content Disclosure via Abilities API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77785"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-77787",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rank Math SEO",
      "cwe": "CWE-862",
      "title": "Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77787"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-81196",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81196"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-81426",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WC Vendors",
      "cwe": "CWE-352",
      "title": "WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81426"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-81432",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetStyleManager for Gutenberg",
      "cwe": "CWE-352",
      "title": "JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81432"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-79621",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CatalogX",
      "cwe": "CWE-345",
      "title": "CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79621"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-81199",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.0072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-200",
      "title": "MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81199"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-4357",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Embed HTML5 Game",
      "cwe": "CWE-434",
      "title": "Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4357"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-77009",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WatchMan-Site7",
      "cwe": "CWE-94",
      "title": "WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77009"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2025-9314",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Developer Tools",
      "cwe": "CWE-434",
      "title": "Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9314"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-19117",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Delinea",
      "product": "Secret Server (On-Prem)",
      "cwe": "CWE-290",
      "title": "Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19117"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-20212",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-1327",
      "title": "Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20212"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-20274",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-664",
      "title": "Cisco IOS XR Software Security Hardening Release: September 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20274"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-20279",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-284",
      "title": "Cisco IOS XR Software Security Hardening Release: September 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20279"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-53611",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AS203038",
      "product": "looking-glass",
      "cwe": "CWE-78",
      "title": "Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53611"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-81294",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paul Ryan",
      "product": "Authorizer",
      "cwe": "CWE-266",
      "title": "WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81294"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-53649",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BishopFox",
      "product": "joro",
      "cwe": "CWE-306",
      "title": "Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53649"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-53670",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vbpf",
      "product": "prevail",
      "cwe": "CWE-682",
      "title": "PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53670"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-53671",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vbpf",
      "product": "prevail",
      "cwe": "CWE-682",
      "title": "PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53671"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-81286",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Lovers",
      "product": "WCFM Marketplace",
      "cwe": "CWE-89",
      "title": "WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81286"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-78689",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX JavaScript",
      "cwe": "CWE-122",
      "title": "NGINX ngx_http_js_module vulnerablility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78689"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-84795",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-269",
      "title": "Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84795"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-66786",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2.17",
      "cwe": "CWE-94",
      "title": "Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66786"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-73475",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Commerce PayPal",
      "cwe": "CWE-863",
      "title": "Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73475"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-82955",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse aeriOS",
      "cwe": "CWE-295",
      "title": "In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS certificate verification when KrakenD retrieves the JSON Web Key Set (JWKS) used to validate bearer tokens, potentially allowing an attacker with the ability to intercept this communication to provide a malicious JWKS and compromise token validation. The issue has been addressed by making the parameter configurable through the boolean Helm value krakend.config.disableJwkSecurity and setting its default value to false, ensuring that TLS certificate verification is enabled by default.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82955"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-18329",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX JavaScript",
      "cwe": "CWE-636",
      "title": "NGINX ngx_http_js_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18329"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-20275",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-682",
      "title": "Cisco IOS XR Software Security Hardening Release: September 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20275"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-20278",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-707",
      "title": "Cisco IOS XR Software Security Hardening Release: September 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20278"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-20280",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-703",
      "title": "Cisco IOS XR Software Security Hardening Release: September 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20280"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-53706",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vbpf",
      "product": "prevail",
      "cwe": "CWE-682",
      "title": "PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PASS for pointer-corrupting programs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53706"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-81283",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP User Frontend",
      "cwe": "CWE-502",
      "title": "WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81283"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-81769",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LiquidThemes",
      "product": "Booking Hub",
      "cwe": "CWE-266",
      "title": "WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81769"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-81772",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms - Layout & Styles",
      "cwe": "CWE-502",
      "title": "WordPress Ninja Forms - Layout & Styles plugin <= 3.0.31 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81772"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-84645",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-94",
      "title": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84645"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-84647",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-502",
      "title": "In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84647"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-84648",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-79",
      "title": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84648"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-84649",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-352",
      "title": "In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84649"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-84650",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-502",
      "title": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84650"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-84668",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins SAML Plugin",
      "cwe": "CWE-284",
      "title": "Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84668"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-84669",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Allure Plugin",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84669"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-84670",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Performance Plugin",
      "cwe": "CWE-502",
      "title": "Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84670"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-84671",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins File Parameter Plugin",
      "cwe": "CWE-22",
      "title": "Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84671"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-84672",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Microsoft Entra ID (previously Azure AD) Plugin",
      "cwe": "CWE-639",
      "title": "Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84672"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-84673",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Customizable Header Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84673"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-84764",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-352",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84764"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-84770",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kitae Park",
      "product": "Mang Board WP",
      "cwe": "CWE-352",
      "title": "WordPress Mang Board WP plugin <= 2.3.8 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84770"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-66842",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "BIG-IP",
      "cwe": "CWE-918",
      "title": "BIG-IP and BIG-IQ Configuration utility vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66842"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-77180",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Ingress Controller",
      "cwe": "CWE-76",
      "title": "NGINX Ingress Controller vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77180"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-78222",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX JavaScript",
      "cwe": "CWE-476",
      "title": "NGINX ngx_http_js_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78222"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-79756",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuclio",
      "product": "nuclio",
      "cwe": "CWE-78",
      "title": "Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79756"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-79989",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-285",
      "title": "Arbitrary user password reset leading to administrator account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79989"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-79990",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-639",
      "title": "GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79990"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-84796",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-639",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84796"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-84801",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84801"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-84851",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "ion-c",
      "cwe": "CWE-674",
      "title": "Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84851"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-20276",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-691",
      "title": "Cisco IOS XR Software Security Hardening Release: September 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20276"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-66362",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Gateway Fabric",
      "cwe": "CWE-76",
      "title": "NGF vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66362"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-82524",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unopim",
      "product": "unopim",
      "cwe": "CWE-434",
      "title": "UnoPim File Upload RCE via TinyMCE Image Upload Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82524"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-84452",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "winml-cli",
      "cwe": "CWE-306",
      "title": "Windows ML CLI: CORS misconfig enables localhost RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84452"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-84803",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84803"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-45730",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuclio",
      "product": "nuclio",
      "cwe": "CWE-862",
      "title": "Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45730"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-82404",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "toon-format",
      "product": "toon",
      "cwe": "CWE-1321",
      "title": "TOON: Prototype pollution when decoding untrusted TOON input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82404"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2025-15485",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Auto x LINE",
      "cwe": "CWE-862",
      "title": "Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15485"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-20277",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-693",
      "title": "Cisco IOS XR Software Security Hardening Release: September 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20277"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-19219",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-345",
      "title": "DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19219"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-84381",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "httpx2",
      "cwe": "CWE-319",
      "title": "HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84381"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-49832",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DSpace",
      "product": "DSpace",
      "cwe": "CWE-94",
      "title": "DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49832"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-52831",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuclio",
      "product": "nuclio",
      "cwe": "CWE-78",
      "title": "Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52831"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-52833",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuclio",
      "product": "nuclio",
      "cwe": "CWE-94",
      "title": "Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52833"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-79755",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuclio",
      "product": "nuclio",
      "cwe": "CWE-78",
      "title": "Nuclio: Unauthenticated OS command injection via function namespace in docker ps --filter label (local Docker platform)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79755"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-84665",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins SonarQube Scanner Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84665"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-78408",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-775",
      "title": "Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78408"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-78410",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-367",
      "title": "Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78410"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-78604",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elastic Agent",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Privilege Escalation to SYSTEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78604"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-84837",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84837"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-84838",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84838"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2023-20576",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Ryzen™ 3000 Series Desktop Processors",
      "cwe": "CWE-345",
      "title": "Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-20576"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2024-7956",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "DataMosaix™ Private Cloud",
      "cwe": "CWE-287",
      "title": "Sensitive Data Exposure and Escalating Privileges Vulnerabilities in DataMosaix™ Private Cloud",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-7956"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-53635",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openedx",
      "product": "openedx-platform",
      "cwe": "CWE-862",
      "title": "Open edX Platform: Insufficient Permission on set_course_mode_price()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53635"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-82958",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Ditto",
      "cwe": "CWE-74",
      "title": "In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON \"thing\" template as raw, un-escaped strings, and then parses the resulting string as JSON. Because the placeholder engine performs no JSON escaping and is unaware of the surrounding JSON string context, a resolved value containing a double-quote character can break out of its string and inject additional JSON structure. When a connection is configured to use this mapper with a template that reflects a header whose value a publishing device can control (for example an MQTT 5 user property, an AMQP 1.0 application property, or a Kafka record header), an attacker able to publish on that connection can inject an inline _policy object. The inline policy overrides the administrator-configured policyId, letting the attacker assign an arbitrary access-control policy to the newly created digital twin — gaining full read/write access to it and potentially revoking the legitimate owner's access, with no administrator interaction. Exploitation requires all of the following: the connection uses the (non-default) ImplicitThingCreation mapper; its template reflects an attacker-controllable header; and, for the policy-override impact, the connection's authorization subjects are permitted to create policies (the default). Deployments that restrict the connection's subjects to thing creation only via the entity-creation configuration are not affected by the policy-override impact.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82958"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-18672",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-22",
      "title": "RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18672"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-20281",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Session Initiation Protocol (SIP) Software",
      "cwe": "CWE-401",
      "title": "Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20281"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-77124",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-184",
      "title": "Nexus Repository 3 - Script Execution Disable Setting Not Enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77124"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-81774",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dotstore",
      "product": "WooCommerce Product Attachment",
      "cwe": "CWE-497",
      "title": "WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81774"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-84292",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-116",
      "title": "fast-uri vulnerable to authority injection via an unvalidated port in serialize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84292"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-84382",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "httpx2",
      "cwe": "CWE-409",
      "title": "HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84382"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-84394",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-436",
      "title": "fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84394"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2023-20577",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "2nd Gen AMD EPYC™ Processors",
      "cwe": "CWE-121",
      "title": "A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-20577"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-84675",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins TICS Plugin",
      "cwe": "CWE-78",
      "title": "OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84675"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-18058",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Motorola",
      "product": "Smart Connect Application",
      "cwe": "CWE-862",
      "title": "The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18058"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-76759",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Screenshot",
      "cwe": "CWE-79",
      "title": "Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76759"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-76782",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Screenshot",
      "cwe": "CWE-79",
      "title": "Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76782"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-78590",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78590"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-14199",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Enterprise",
      "cwe": "CWE-290",
      "title": "Session takeover via Auth Proxy cache key collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14199"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-49249",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "malach-it",
      "product": "boruta-server",
      "cwe": "CWE-400",
      "title": "Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49249"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-77125",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-863",
      "title": "Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77125"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-79754",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuclio",
      "product": "nuclio",
      "cwe": "CWE-77",
      "title": "Nuclio: Kaniko build tempDir command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79754"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-79991",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-89",
      "title": "Authenticated SQL Injection via nested eager-loading criteria",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79991"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-81288",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Upsell Order Bump Offer for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81288"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-81289",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sonaar",
      "product": "MP3 Audio Player for Music, Radio & Podcast by Sonaar",
      "cwe": "CWE-79",
      "title": "WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.13.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81289"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-81770",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MapGeo",
      "product": "Interactive Geo Maps",
      "cwe": "CWE-79",
      "title": "WordPress Interactive Geo Maps plugin <= 1.6.30 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81770"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-81771",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TrustedSite",
      "product": "TrustedSite",
      "cwe": "CWE-79",
      "title": "WordPress TrustedSite plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81771"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-81775",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Estatik",
      "product": "Estatik",
      "cwe": "CWE-79",
      "title": "WordPress Estatik plugin <= 4.3.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81775"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-84667",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins ThinBackup Plugin",
      "cwe": "CWE-22",
      "title": "Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84667"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-84759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elementor",
      "product": "Activity Log",
      "cwe": "CWE-352",
      "title": "WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84759"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-84794",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84794"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-84798",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84798"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-84800",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84800"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-84809",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tencent",
      "product": "AI-Infra-Guard",
      "cwe": "CWE-693",
      "title": "Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84809"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-84810",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "claude-world",
      "product": "claude-skill-antivirus",
      "cwe": "CWE-693",
      "title": "claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84810"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-84811",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agentverus",
      "product": "agentverus-scanner",
      "cwe": "CWE-693",
      "title": "agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84811"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-78409",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-59",
      "title": "Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78409"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-75135",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Septeo IT Solutions",
      "product": "UpSignOn",
      "cwe": "CWE-316",
      "title": "UpSignOn < 7.19.0 Sensitive Key Retention in Memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75135"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-75136",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Septeo IT Solutions",
      "product": "UpSignOn",
      "cwe": "CWE-522",
      "title": "UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75136"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-75137",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Septeo IT Solutions",
      "product": "UpSignOn",
      "cwe": "CWE-316",
      "title": "UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75137"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-84886",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simular-ai",
      "product": "Agent-S",
      "cwe": "CWE-400",
      "title": "simular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84886"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-12704",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Enterprise",
      "cwe": "CWE-294",
      "title": "SAML assertion replay via skipped InResponseTo validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12704"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-55421",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openedx",
      "product": "openedx-platform",
      "cwe": "CWE-918",
      "title": "Open edX Platform: SSRF in Studio Video Download Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55421"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-82884",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All in One SEO",
      "cwe": "CWE-79",
      "title": "All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82884"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-83547",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Xpro Addons",
      "cwe": "CWE-79",
      "title": "Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Widgets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83547"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-10821",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Yoast SEO Premium",
      "cwe": "CWE-74",
      "title": "Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10821"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-2688",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "HIPAA FORMS",
      "cwe": "CWE-863",
      "title": "CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2688"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-19475",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "PostgreSQL Datasource",
      "cwe": "CWE-400",
      "title": "SQL Data Source Plugin: OOM DoS via $__timeGroup macro",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19475"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-55221",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "malach-it",
      "product": "boruta-server",
      "cwe": "CWE-532",
      "title": "Boruta: OAuth credentials exposed in Boruta business logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55221"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-78586",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78586"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-78588",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Filebeat",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78588"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-78599",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-22",
      "title": "Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78599"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-82223",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event SOlution",
      "cwe": "CWE-862",
      "title": "WordPress WP Event SOlution plugin <= 4.1.22 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82223"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-83562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Lovers",
      "product": "WCFM Marketplace",
      "cwe": "CWE-79",
      "title": "WordPress WCFM Marketplace plugin <= 3.8.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83562"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-84377",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-918",
      "title": "LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84377"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-84781",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Gallery PhotoBlocks",
      "cwe": "CWE-79",
      "title": "WordPress Gallery PhotoBlocks plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84781"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-53600",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dignifiedquire",
      "product": "async-tar",
      "cwe": "CWE-20",
      "title": "async-tar PAX extension-header desync enables tar entry/content smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53600"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-78591",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78591"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-84376",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-187",
      "title": "Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84376"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-84651",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-284",
      "title": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84651"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-85084",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "TizenFX",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in TizenFX MediaBufferBase indexer setter due to missing bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85084"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-32773",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Spark",
      "cwe": "CWE-80",
      "title": "Apache Spark: XSS Vulnerability in Spark Web 3.5.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32773"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-81160",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Slick Carousel",
      "cwe": "CWE-79",
      "title": "Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81160"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-81201",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Monster Menus",
      "cwe": "CWE-79",
      "title": "Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81201"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-77123",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-201",
      "title": "Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77123"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2024-3773",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LiveJournal Shortcode",
      "cwe": "CWE-79",
      "title": "LiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-3773"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-20354",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-354",
      "title": "Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20354"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-20355",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-345",
      "title": "Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20355"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-76755",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Gammu SMS Daemon",
      "cwe": "CWE-119",
      "title": "Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76755"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-76756",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Gammu SMS Daemon",
      "cwe": "CWE-119",
      "title": "Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76756"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-76757",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Gammu SMS Daemon",
      "cwe": "CWE-119",
      "title": "Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76757"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-76758",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Link content parser",
      "cwe": "CWE-20",
      "title": "Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76758"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-84378",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "httpx2",
      "cwe": "CWE-407",
      "title": "HTTPX2: Quadratic SSE line buffering can cause CPU denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84378"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-84380",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "httpx2",
      "cwe": "CWE-444",
      "title": "HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84380"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-14255",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Shared Components",
      "cwe": "CWE-674",
      "title": "IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14255"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-49831",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DSpace",
      "product": "DSpace",
      "cwe": "CWE-22",
      "title": "DSpace: Curation Task Reporter output path is not restricted to trusted directories (Path Traversal Vulnerability)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49831"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-49833",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DSpace",
      "product": "DSpace",
      "cwe": "CWE-22",
      "title": "DSpace: Path Traversal possible in LDN message generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49833"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-78601",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78601"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-84772",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Broken Link Checker",
      "cwe": "CWE-918",
      "title": "WordPress Broken Link Checker plugin <= 2.4.14 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84772"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-84839",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tsi-coop",
      "product": "tsi-dpdp-cms",
      "cwe": "CWE-287",
      "title": "tsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84839"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-84840",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tsi-coop",
      "product": "tsi-dpdp-cms",
      "cwe": "CWE-287",
      "title": "tsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84840"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-84841",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tsi-coop",
      "product": "tsi-dpdp-cms",
      "cwe": "CWE-602",
      "title": "tsi-coop tsi-dpdp-cms client-side enforcement of server-side security",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84841"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-84856",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rowboatlabs",
      "product": "rowboat",
      "cwe": "CWE-404",
      "title": "rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84856"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-84857",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sigoden",
      "product": "aichat",
      "cwe": "CWE-400",
      "title": "sigoden aichat API Endpoint serve.rs memory allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84857"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-2811",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ajaxify Comments",
      "cwe": "CWE-113",
      "title": "Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2811"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-8151",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Membership MailChimp Integration",
      "cwe": "CWE-352",
      "title": "Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8151"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-66652",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Grand Tour",
      "cwe": "CWE-352",
      "title": "WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66652"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-73476",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "External Authentication",
      "cwe": "CWE-178",
      "title": "External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73476"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-78598",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78598"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-78609",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Eck Operator",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78609"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-81164",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Entity PDF",
      "cwe": "CWE-862",
      "title": "Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81164"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-84217",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mamunur Rashid",
      "product": "Classified Listing",
      "cwe": "CWE-862",
      "title": "WordPress Classified Listing plugin <= 6.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84217"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-84654",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-472",
      "title": "In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration forms to modify public static fields of the configuration objects those forms are bound to, resulting in changes that apply globally to the Jenkins instance.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84654"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-84660",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Build Step Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84660"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-84661",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Build Step Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84661"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-84663",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Groovy Libraries Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84663"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-84664",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins GitLab Plugin",
      "cwe": "CWE-471",
      "title": "Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84664"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-84674",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins XebiaLabs XL Deploy Plugin",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84674"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-84677",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins update-center2",
      "cwe": "CWE-79",
      "title": "Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84677"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2025-8945",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Wp Edit Password Protected",
      "cwe": "CWE-863",
      "title": "Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8945"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2025-15481",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Notification Bar for WordPress",
      "cwe": "CWE-306",
      "title": "Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15481"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2025-15489",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Passster",
      "cwe": "CWE-863",
      "title": "Passster < 4.2.24 - Password Protection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15489"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2025-15490",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Passster",
      "cwe": "CWE-863",
      "title": "Passster < 4.2.26 - Global Protection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15490"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-17563",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Frontend",
      "cwe": "CWE-862",
      "title": "WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17563"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-73474",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Entity Share Websub",
      "cwe": "CWE-918",
      "title": "Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73474"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-73477",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Quick Tabs",
      "cwe": "CWE-863",
      "title": "Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73477"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-73478",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Diff",
      "cwe": "CWE-863",
      "title": "Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73478"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-77121",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-770",
      "title": "Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77121"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-77122",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository 3",
      "cwe": "CWE-863",
      "title": "Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metadata via Group Repository Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77122"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-77793",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RegistrationMagic",
      "cwe": "CWE-602",
      "title": "RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77793"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-77794",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RegistrationMagic",
      "cwe": "CWE-472",
      "title": "RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77794"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-78153",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Restrict User Access",
      "cwe": "CWE-863",
      "title": "Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78153"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-78602",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elastic Maps Server",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78602"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-81158",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Entity API",
      "cwe": "CWE-863",
      "title": "Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81158"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-81162",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "DXPR Builder: The Best Editing (AI) Experience for Drupal",
      "cwe": "CWE-201",
      "title": "DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81162"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-81165",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Blazy",
      "cwe": "CWE-863",
      "title": "Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81165"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-81166",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Digital Signage Framework",
      "cwe": "CWE-862",
      "title": "Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81166"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-81205",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "LDAP / Active Directory Integration",
      "cwe": "CWE-90",
      "title": "LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81205"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-81269",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Data field",
      "cwe": "CWE-862",
      "title": "Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81269"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-82522",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libjxl",
      "product": "libjxl",
      "cwe": "CWE-681",
      "title": "libjxl < 0.12.0 Container Box Parser Integer Underflow via 32-bit Size Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82522"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-83533",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Express Checkout",
      "cwe": "CWE-345",
      "title": "WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83533"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-84379",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "httpx2",
      "cwe": "CWE-93",
      "title": "HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84379"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-84760",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Ultimate Gift Cards For WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84760"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-84771",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Permissions",
      "cwe": "CWE-639",
      "title": "WordPress PublishPress Permissions plugin <= 4.8.3 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84771"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-84775",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Really Simple Plugins",
      "product": "Really Simple SSL",
      "cwe": "CWE-770",
      "title": "WordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84775"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-84780",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPGMaps",
      "product": "WP Go Maps",
      "cwe": "CWE-770",
      "title": "WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84780"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-84792",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS before 5.10.11 Broken Access Control via element-indexes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84792"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-84797",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84797"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-84799",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-285",
      "title": "Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84799"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-84802",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84802"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-84804",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimai",
      "product": "kimai",
      "cwe": "CWE-284",
      "title": "Kimai before 2.65.0 Authorization Bypass via Team Activity API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84804"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-84805",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimai",
      "product": "kimai",
      "cwe": "CWE-862",
      "title": "Kimai 2.61.0 before 2.63.0 Authentication Bypass via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84805"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-84806",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimai",
      "product": "kimai",
      "cwe": "CWE-732",
      "title": "Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84806"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-84807",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimai",
      "product": "kimai",
      "cwe": "CWE-266",
      "title": "Kimai before 2.65.0 Authentication Bypass via Team Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84807"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-84808",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kimai",
      "product": "kimai",
      "cwe": "CWE-863",
      "title": "Kimai before 2.65.0 Authorization Bypass via API Timesheet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84808"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-84835",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DimaFreund",
      "product": "Rentsyst",
      "cwe": "CWE-862",
      "title": "WordPress Rentsyst plugin <= 2.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84835"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-84885",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simular-ai",
      "product": "Agent-S",
      "cwe": "CWE-404",
      "title": "simular-ai Agent-S CodeAgent code_agent.py denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84885"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-84887",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simular-ai",
      "product": "Agent-S",
      "cwe": "CWE-404",
      "title": "simular-ai Agent-S Model-generated GUI Action Execution Workflow grounding.py denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84887"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-84888",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RightNow-AI",
      "product": "OpenFang",
      "cwe": "CWE-789",
      "title": "RightNow-AI OpenFang tool_runner.rs shell_exec memory allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84888"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-75134",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEOWriting",
      "product": "SEOWriting",
      "cwe": "CWE-79",
      "title": "SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75134"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-52832",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuclio",
      "product": "nuclio",
      "cwe": "CWE-22",
      "title": "Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52832"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-78594",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Apm Server",
      "cwe": "CWE-409",
      "title": "Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78594"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-18986",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Entity Browser",
      "cwe": "CWE-79",
      "title": "Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18986"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-81167",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Address Suggestion",
      "cwe": "CWE-79",
      "title": "Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81167"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-81571",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Brave",
      "cwe": "CWE-74",
      "title": "Brave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution via UTM Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81571"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-84793",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84793"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-53636",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openedx",
      "product": "openedx-platform",
      "cwe": "CWE-294",
      "title": "Open edX LTI OAuth Replay Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53636"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-49830",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DSpace",
      "product": "DSpace",
      "cwe": "CWE-20",
      "title": "DSpace: ORE resource URI does not validate scheme for non-web resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49830"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-78584",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-204",
      "title": "Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78584"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-82293",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82293"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-84646",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-502",
      "title": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84646"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-84655",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-116",
      "title": "Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84655"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-84656",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84656"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-84658",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-200",
      "title": "Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84658"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-84659",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-862",
      "title": "Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the \"Force the use of the sandbox globally in the system\" setting, allowing attackers to disable it through Stapler data binding.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84659"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-84662",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins LDAP Plugin",
      "cwe": "CWE-601",
      "title": "Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84662"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-84676",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Parameterized Remote Trigger Plugin",
      "cwe": "CWE-311",
      "title": "Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84676"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-84657",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-862",
      "title": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84657"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-14326",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Timetics",
      "cwe": "CWE-639",
      "title": "Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14326"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-81159",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Commerce CyberSource",
      "cwe": "CWE-208",
      "title": "Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81159"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-81168",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "CAPTCHA Protected Page",
      "cwe": "CWE-288",
      "title": "CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81168"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2025-15692",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Icegram Express",
      "cwe": "CWE-79",
      "title": "Icegram Express < 5.8.6 - Admin+ Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15692"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-19698",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GutenKit",
      "cwe": "CWE-74",
      "title": "GutenKit < 2.5.1 - Contributor+ Stored CSS Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19698"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-78600",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Eck Operator",
      "cwe": "CWE-459",
      "title": "Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential Retention",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78600"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2023-3360",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Weaver Show Posts",
      "cwe": "CWE-502",
      "title": "Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-3360"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-81161",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Content Moderation Notifications",
      "cwe": "CWE-267",
      "title": "Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81161"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-78587",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Fleet Server",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78587"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-63020",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "BIG-IP",
      "cwe": "CWE-451",
      "title": "BIG-IP Configuration utility vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63020"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-84833",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntegrals",
      "product": "openbrowser",
      "cwe": "CWE-400",
      "title": "ntegrals openbrowser Browser Agent Message Construction agent.ts resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84833"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-84852",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Reader Tools",
      "product": "PDF Reader App",
      "cwe": "CWE-22",
      "title": "Reader Tools PDF Reader App File ActSplashNew.handleDeeplink path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84852"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-16647",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Disable Login Page",
      "cwe": "CWE-288",
      "title": "Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16647"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-56855",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": null,
      "title": "Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56855"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-78662",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": null,
      "title": "Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78662"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-84652",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": null,
      "title": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the \"remember me\" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the \"remember me\" cookie, grants the attacker access to Jenkins as that user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84652"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-84653",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": null,
      "title": "Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84653"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-84666",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Job Configuration History Plugin",
      "cwe": null,
      "title": "Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84666"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-48710",
      "detail": "ADDED TO KEV — CVE-2026-48710 (Kludex starlette). Remediation due September 16, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-49869",
      "detail": "ADDED TO KEV — CVE-2026-49869 (kestra-io kestra). Remediation due September 5, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-59822",
      "detail": "ADDED TO KEV — CVE-2026-59822 (BerriAI litellm). Remediation due September 16, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-82329",
      "detail": "ADDED TO KEV — CVE-2026-82329 (jfrog artifactory). Remediation due September 5, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-83548",
      "detail": "ADDED TO KEV — CVE-2026-83548 (SonicWall SMA1000). Remediation due September 5, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-83549",
      "detail": "ADDED TO KEV — CVE-2026-83549 (SonicWall SMA1000). Remediation due September 5, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-9586",
      "detail": "ADDED TO KEV — CVE-2026-9586 (Sangoma Switchvox SMB Edition). Remediation due September 5, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16253",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16253 (Unknown Total Upkeep). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25550",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25551",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25551 (Seagull Software, LLC. BarTender 2021). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-30922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41242",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42264 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42579 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48020",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48020 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48491",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48491 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49869",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49869 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53622",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53622 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58380",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 8). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62384",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62384 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66758",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76221 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76222",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76222 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78675",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78675 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78676",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78676 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78677",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78677 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78678",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78678 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82641",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82641 (Keploy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82669",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82669 (klaussilveira GitList). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82679",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82679 (diem-project diem). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82691",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82691 (D-Link DNS-320L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82696",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82696 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82701",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82701 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82803",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82803 (armink struct2json). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82810",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82810 (extension.vn 2FA Authenticator Extension). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82817",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82817 (dibo-software diboot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82834",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82834 (Doccano Open Source Annotation Tools for Machine Learning Practitioners). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82876",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82876 (Phison Electronics Corporation PS3111-S11 Controller Firmware). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82909",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82909 (QuantumNous new-api). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-83744",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-83744 (invoiceninja Invoice Ninja). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84288",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84288 (NousResearch hermes-agent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84289",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84289 (NousResearch hermes-agent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-9586",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-9586 (Sangoma Switchvox SMB Edition). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-20579",
      "detail": "RESCORED — CVE-2023-20579 (AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics  ). CVSS 3.4 → 6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16821",
      "detail": "RESCORED — CVE-2026-16821 (IBM AIX). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18504",
      "detail": "RESCORED — CVE-2026-18504 (fastify). CVSS 5.4 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19478",
      "detail": "RESCORED — CVE-2026-19478 (GitLab). CVSS 9.4 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-24184",
      "detail": "RESCORED — CVE-2026-24184 (NVIDIA Cumulus Linux GA). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47606",
      "detail": "RESCORED — CVE-2026-47606 (NVIDIA Triton Inference Server). CVSS 6.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47864",
      "detail": "RESCORED — CVE-2026-47864 (Spring Integration). CVSS 6.4 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47875",
      "detail": "RESCORED — CVE-2026-47875 (Spring Batch). CVSS 5.6 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47877",
      "detail": "RESCORED — CVE-2026-47877 (Spring Security). CVSS 8.2 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49096",
      "detail": "RESCORED — CVE-2026-49096 (Elastic Kibana). CVSS 4.3 → 3.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59277",
      "detail": "RESCORED — CVE-2026-59277 (Spring Security). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59297",
      "detail": "RESCORED — CVE-2026-59297 (Spring Cloud Function). CVSS 3.1 → 3.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59298",
      "detail": "RESCORED — CVE-2026-59298 (Spring Cloud Function). CVSS 3.1 → 3.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59299",
      "detail": "RESCORED — CVE-2026-59299 (Spring Cloud Function). CVSS 3.1 → 3.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59300",
      "detail": "RESCORED — CVE-2026-59300 (Spring Cloud Function). CVSS 3.1 → 3.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-66376",
      "detail": "RESCORED — CVE-2026-66376 (jfrog artifactory). CVSS 4.2 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71474",
      "detail": "RESCORED — CVE-2026-71474 (Red Hat Advanced Cluster Management for Kubernetes 2.11). CVSS 6.5 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71475",
      "detail": "RESCORED — CVE-2026-71475 (Red Hat Advanced Cluster Management for Kubernetes 2.13). CVSS 5 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7680",
      "detail": "RESCORED — CVE-2026-7680 (jsbroks COCO Annotator). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78607",
      "detail": "RESCORED — CVE-2026-78607 (Elasticsearch). CVSS 5.4 → 7.1 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-39909",
      "detail": "REJECTED — CVE-2026-39909 (ggml-org llama.cpp). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2023-50224",
      "detail": "PATCH SHIPPED — CVE-2023-50224 (TP-Link TL-WR841N). Fixed in TL-WR841N V11_211209."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66780",
      "detail": "PATCH SHIPPED — CVE-2026-66780 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1788105072."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66782",
      "detail": "PATCH SHIPPED — CVE-2026-66782 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1788105072."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66783",
      "detail": "PATCH SHIPPED — CVE-2026-66783 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1788105072."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66785",
      "detail": "PATCH SHIPPED — CVE-2026-66785 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023916."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66787",
      "detail": "PATCH SHIPPED — CVE-2026-66787 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023916."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66788",
      "detail": "PATCH SHIPPED — CVE-2026-66788 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023916."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-82641",
      "detail": "PATCH SHIPPED — CVE-2026-82641 (Keploy). Fixed in Keploy 3.6.26."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-27010",
      "detail": "ENRICHED — CVE-2024-27010 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-58095",
      "detail": "ENRICHED — CVE-2024-58095 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-22104",
      "detail": "ENRICHED — CVE-2025-22104 (Linux). Received CVSS 7.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-38203",
      "detail": "ENRICHED — CVE-2025-38203 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-38237",
      "detail": "ENRICHED — CVE-2025-38237 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64049",
      "detail": "ENRICHED — CVE-2026-64049 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64052",
      "detail": "ENRICHED — CVE-2026-64052 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64054",
      "detail": "ENRICHED — CVE-2026-64054 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64059",
      "detail": "ENRICHED — CVE-2026-64059 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64060",
      "detail": "ENRICHED — CVE-2026-64060 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64062",
      "detail": "ENRICHED — CVE-2026-64062 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64063",
      "detail": "ENRICHED — CVE-2026-64063 (Linux). Received CVSS 7.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
