{
  "day": "2026-09-03",
  "boundary": "UTC calendar day",
  "published_count": 346,
  "by_severity": {
    "CRITICAL": 40,
    "HIGH": 172,
    "MEDIUM": 108,
    "LOW": 10
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 16,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-85040",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.01639,
      "epss_percentile": 0.74717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZhongBangKeJi",
      "product": "CRMEB",
      "cwe": "CWE-77",
      "title": "ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85040"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-84830",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01068,
      "epss_percentile": 0.62523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEPPmail AG",
      "product": "Secure Email Gateway",
      "cwe": "CWE-78",
      "title": "OS command injection in privileged configuration handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84830"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-84832",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0061,
      "epss_percentile": 0.46878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEPPmail AG",
      "product": "SEPPmail Secure Email Gateway (SEG)",
      "cwe": "CWE-78",
      "title": "Unsafe deserialization in the REST interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84832"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-85031",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00579,
      "epss_percentile": 0.45432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "CP450",
      "cwe": "CWE-119",
      "title": "TOTOLINK CP450 cstecgi.cgi buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85031"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-85100",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00522,
      "epss_percentile": 0.42321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "2FastLabs",
      "product": "agent-squad",
      "cwe": "CWE-400",
      "title": "2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeRequest resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85100"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-76174",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00487,
      "epss_percentile": 0.40057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OCS Inventory NG",
      "product": "Ocsreports",
      "cwe": "CWE-434",
      "title": "Multiple vulnerabilities in Ocsreports for OCS Inventory NG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76174"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-84831",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEPPmail AG",
      "product": "SEPPmail Secure Email Gateway (SEG)",
      "cwe": "CWE-287",
      "title": "Mandatory MFA bypass before enrollment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84831"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-85091",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zlib",
      "product": "zlib",
      "cwe": "CWE-787",
      "title": "zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85091"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-85089",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-908",
      "title": "FreeRDP before 3.31.0 Information Disclosure via uninitialized heap memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85089"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-74769",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0038,
      "epss_percentile": 0.31059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-863",
      "title": "Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74769"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-85021",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00368,
      "epss_percentile": 0.29772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langgenius",
      "product": "dify",
      "cwe": "CWE-79",
      "title": "langgenius dify Splash Layout splash.tsx router.replace cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85021"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-85030",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00355,
      "epss_percentile": 0.28488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "AI-Trader",
      "cwe": "CWE-840",
      "title": "HKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85030"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-17539",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "RTU500 series CMU firmware",
      "cwe": "CWE-476",
      "title": "RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17539"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-80254",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.27885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shizen Connect Inc.",
      "product": "ShizenBox2 (edge-app)",
      "cwe": "CWE-639",
      "title": "Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80254"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-68860",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.27795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-188",
      "title": "Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68860"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-74768",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.27778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-918",
      "title": "Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74768"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-76177",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OCS Inventory NG",
      "product": "Ocsreports",
      "cwe": "CWE-918",
      "title": "Multiple vulnerabilities in Ocsreports for OCS Inventory NG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76177"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-76175",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OCS Inventory NG",
      "product": "Ocsreports",
      "cwe": "CWE-89",
      "title": "Multiple vulnerabilities in Ocsreports for OCS Inventory NG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76175"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-76176",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OCS Inventory NG",
      "product": "Ocsreports",
      "cwe": "CWE-89",
      "title": "Multiple vulnerabilities in Ocsreports for OCS Inventory NG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76176"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-80253",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shizen Connect Inc.",
      "product": "ShizenBox2 (dev-conf)",
      "cwe": "CWE-1263",
      "title": "An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80253"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-85093",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cheshire-cat-ai",
      "product": "core",
      "cwe": "CWE-863",
      "title": "Cheshire Cat AI Memory Collection Endpoint Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85093"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-85090",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.2229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-125",
      "title": "FreeRDP before 3.31.0 Heap Out-of-Bounds Read via AVC444",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85090"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-85022",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.18808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langgenius",
      "product": "dify",
      "cwe": "CWE-79",
      "title": "langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85022"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-2573",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ataurr",
      "product": "GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor",
      "cwe": "CWE-79",
      "title": "GutenKit <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2573"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-3852",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elegant Themes",
      "product": "Divi",
      "cwe": "CWE-79",
      "title": "Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3852"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-80731",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80731"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-80744",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00226,
      "epss_percentile": 0.13193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80744"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-80752",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: psxpad-spi - set driver data before use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80752"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-80732",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ata: pata_sl82c105: fix bridge revision use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80732"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-80737",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: amba-pl011: synchronize DMA teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80737"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-80754",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Input: synaptics-rmi4 - fix F55 transmitter electrode count typo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80754"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-80733",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: remove WARN_ON_ONCE() from sk_mc_loop()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80733"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-80742",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "af_packet: Don't send zero-byte data in tpacket_snd().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80742"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-80743",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80743"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-80756",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: do not cancel a policy conversion that never started",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80756"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-80757",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: reject a class permission count below its inherited common",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80757"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-80728",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00209,
      "epss_percentile": 0.10976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Revert \"drm/amdgpu: fix aperture mapping leak\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80728"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-80735",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: ensure socket is owned by ovpn before deref sk_user_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80735"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-80740",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.10695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/log: Fix infinite loop when scale is too large for display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80740"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-80726",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00205,
      "epss_percentile": 0.10554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80726"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-80730",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00205,
      "epss_percentile": 0.10555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Fix crash passing ERR_PTR to kthread_stop()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80730"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-80736",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.09821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thunderbolt: Fix bandwidth group reservation indexing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80736"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-80749",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.0982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/connector/hdmi: Fix out of bounds memory read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80749"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-80727",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.09821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/mce: Set up the polling timer before CMCI discovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80727"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-80739",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.0982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80739"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-80755",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.002,
      "epss_percentile": 0.09822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: reject a permission value exceeding the class permission count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80755"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-80734",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: initialize inode mapping flags for cached inodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80734"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-80745",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "regulator: fp9931: Fix VPOS/VNEG voltage selector table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80745"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-80750",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pmdomain: mediatek: fix remaining %pOF after of_node_put()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80750"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-80753",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovpn: run deferred work on a module-owned workqueue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80753"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-80748",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: loongson2: Fix sg iteration in data reorder functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80748"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-80738",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.0956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80738"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-80741",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/log: Fix out-of-bounds read on empty message length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80741"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-80747",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Add bounds check for CRAT subtype length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80747"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-80751",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80751"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-9852",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "MicroSCADA SYS600",
      "cwe": "CWE-1236",
      "title": "A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9852"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-80729",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/huge_memory: initialise workingset state before folio split",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80729"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-80746",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00189,
      "epss_percentile": 0.08583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80746"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-73600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.07955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-121",
      "title": "Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73600"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-76642",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.05975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "util-linux",
      "product": "util-linux",
      "cwe": "CWE-390",
      "title": "util-linux libmount Privilege Escalation via Failed Mount Helper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76642"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2021-38489",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Insyde Software",
      "product": "InsydeH2O",
      "cwe": "CWE-256",
      "title": "HDD Password Stored In Plaintext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-38489"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-85092",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jtsylve",
      "product": "LiME",
      "cwe": "CWE-59",
      "title": "LiME through 1.12.0 Arbitrary File Overwrite via Symlink Following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85092"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2021-43614",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.02986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Insyde Software",
      "product": "InsydeH2O",
      "cwe": "CWE-120",
      "title": "VariableEditSmm: Error checking of UEFI variables could cause buffer overflow, leading to code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-43614"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-9853",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "MicroSCADA SYS600",
      "cwe": "CWE-303",
      "title": "A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9853"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-9854",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "MicroSCADA SYS600",
      "cwe": "CWE-303",
      "title": "A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9854"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2021-43613",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Insyde Software",
      "product": "InsydeH2O",
      "cwe": "CWE-732",
      "title": "SysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leading to escalation of privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-43613"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-70352",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure AI Language Authoring",
      "cwe": "CWE-306",
      "title": "Azure AI Language Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70352"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-83711",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Entra",
      "cwe": "CWE-639",
      "title": "Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83711"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-85061",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maplibre",
      "product": "maplibre-gl-js",
      "cwe": "CWE-79",
      "title": "MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85061"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-84238",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITH",
      "product": "YITH Request a Quote for WooCommerce Premium",
      "cwe": "CWE-862",
      "title": "WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84238"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-84753",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "Mail Mint",
      "cwe": "CWE-502",
      "title": "WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84753"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-84814",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bricksforge.",
      "product": "Bricksforge",
      "cwe": "CWE-266",
      "title": "WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84814"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-84834",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eyecix",
      "product": "JobSearch",
      "cwe": "CWE-502",
      "title": "WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84834"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-85042",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85042"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-85047",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85047"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-85050",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85050"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-78069",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-862",
      "title": "Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78069"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-82180",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Arrowhead",
      "cwe": "CWE-290",
      "title": "In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message payload (the authentication field of MqttRequestTemplate) and treats its Subject DN as the authenticated identity. The certificate is decoded with CertificateFactory.generateCertificate() but its signature is never verified and its issuer chain is never validated against any trust store. Authorisation is reduced to two string comparisons on attacker-supplied data: the DN-qualifier must equal \"sy\" or \"op\", and the cloud-name part of the CN must match the server's. Both values are public (the cloud name is in the server's own TLS certificate). An attacker who can publish to the MQTT broker can therefore mint a self-signed certificate with CN=Sysop.<cloud>.<org>.arrowhead.eu, dnQualifier=op, send it as the authentication field, and be authenticated as the cloud's system operator with isSysOp == true. This passes the downstream ManagementServiceMqttFilter (request.isSysOp() → allowed) and gives full management access over MQTT. The HTTP CertificateFilter is not affected — it reads the certificate from jakarta.servlet.request.X509Certificate, which Tomcat populates only after a successful mTLS handshake against the configured trust store.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82180"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-85216",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-521",
      "title": "MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85216"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-78080",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joodb.feenders.de",
      "product": "JooDatabase Lite extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78080"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-80098",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Copilot Studio",
      "cwe": "CWE-347",
      "title": "Copilot Studio Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80098"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-82526",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SciPhi-AI",
      "product": "R2R",
      "cwe": "CWE-89",
      "title": "R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82526"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-84768",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikAppointments Services Booking Calendar",
      "cwe": "CWE-89",
      "title": "WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84768"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-84813",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-89",
      "title": "WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84813"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-85154",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-269",
      "title": "WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85154"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-85181",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dianping",
      "product": "cat",
      "cwe": "CWE-565",
      "title": "CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85181"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-85183",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Avaiga",
      "product": "taipy",
      "cwe": "CWE-1385",
      "title": "Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85183"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-85391",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Peppermint-Lab",
      "product": "peppermint",
      "cwe": "CWE-798",
      "title": "Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85391"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-85394",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mpdavis",
      "product": "python-jose",
      "cwe": "CWE-347",
      "title": "python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85394"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-85424",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-306",
      "title": "MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85424"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-85425",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-78",
      "title": "MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85425"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-85426",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-78",
      "title": "MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85426"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-85428",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-306",
      "title": "MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85428"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-85433",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "essential-moos",
      "cwe": "CWE-862",
      "title": "MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85433"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-85434",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-345",
      "title": "MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85434"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-85435",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-345",
      "title": "MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85435"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-85437",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-787",
      "title": "MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85437"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-85438",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-190",
      "title": "MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85438"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-85440",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-787",
      "title": "MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85440"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-67402",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "ConfigServer Security & Firewall",
      "cwe": "CWE-552",
      "title": "An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67402"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-76178",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OCS Inventory NG",
      "product": "Ocsreports",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in Ocsreports for OCS Inventory NG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76178"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-85427",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "essential-moos",
      "cwe": "CWE-494",
      "title": "MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85427"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-58400",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geonetwork",
      "product": "core-geonetwork",
      "cwe": "CWE-94",
      "title": "GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58400"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-62916",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-288",
      "title": "Microsoft Entra ID Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62916"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-80515",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Arrowhead",
      "cwe": "CWE-647",
      "title": "In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains(\"/mgmt/\"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \\ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80515"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-85109",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG10",
      "cwe": "CWE-119",
      "title": "Tenda HG10 Boa Web Server formLogin buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85109"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-78064",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78064"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-80465",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Mendix SAML (Mendix 10 compatible)",
      "cwe": "CWE-347",
      "title": "A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80465"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-84752",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rometheme",
      "product": "RTMKit",
      "cwe": "CWE-502",
      "title": "WordPress RTMKit plugin <= 2.1.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84752"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-85046",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85046"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-85049",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85049"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-85051",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85051"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-85053",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-668",
      "title": "Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85053"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-85199",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse aeriOS",
      "cwe": "CWE-22",
      "title": "Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem paths without adequate validation or sanitization. An unauthenticated remote attacker able to access the Self-orchestrator API could therefore supply specially crafted identifiers containing path traversal sequences to write or delete JSON files outside the intended application directories, subject to the filesystem permissions of the Self-orchestrator process. The impact is increased by the absence of authentication on the affected API and by the container running with elevated privileges in the affected deployment configuration. The issue has been addressed in version 1.2.1 by introducing validation and sanitization of user-controlled identifiers before they are used to construct filesystem paths, preventing path separator characters from being used to escape the intended directories.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85199"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-85236",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-352",
      "title": "MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85236"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-85430",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "essential-moos",
      "cwe": "CWE-345",
      "title": "MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85430"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-85432",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-290",
      "title": "MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85432"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-85455",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-125",
      "title": "MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85455"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-53924",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Hive",
      "product": "gardens-v2",
      "cwe": "CWE-284",
      "title": "Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53924"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-57445",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Hive",
      "product": "gardens-v2",
      "cwe": "CWE-703",
      "title": "Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57445"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-71404",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-639",
      "title": "Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71404"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-77999",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-472",
      "title": "Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77999"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-82520",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "domainaware",
      "product": "parsedmarc",
      "cwe": "CWE-409",
      "title": "parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82520"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-82527",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SciPhi-AI",
      "product": "R2R",
      "cwe": "CWE-89",
      "title": "R2R 3.6.6 SQL Injection via Retrieval Search Filter Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82527"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-85155",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-89",
      "title": "WWBN AVideo SQL Injection via get.json.php APIName channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85155"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-85169",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-94",
      "title": "n8n before 1.123.73 Remote Code Execution via $fromAI Prototype Leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85169"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-85174",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-532",
      "title": "SiYuan before v3.8.2 API Token Exposure via Log File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85174"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-85175",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-552",
      "title": "SiYuan before v3.8.2 TLS Private Key Disclosure via getFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85175"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-85176",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbgate",
      "product": "dbgate",
      "cwe": "CWE-73",
      "title": "DbGate through 7.2.6 Arbitrary File Read and Write via file:// jslid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85176"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-85180",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ollama",
      "product": "ollama",
      "cwe": "CWE-918",
      "title": "Ollama 0.30.0 through 0.33.2 SSRF via Cross-Host Tensor Blob Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85180"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-85212",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crmeb",
      "product": "CRMEB",
      "cwe": "CWE-862",
      "title": "CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85212"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-85393",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digitalbazaar",
      "product": "forge",
      "cwe": "CWE-347",
      "title": "node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85393"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-85396",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rubyzip",
      "product": "rubyzip",
      "cwe": "CWE-22",
      "title": "rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85396"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-85429",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-345",
      "title": "MOOS-IvP through 24.8.1 uFldNodeComms Node Message Source Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85429"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-85431",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "essential-moos",
      "cwe": "CWE-345",
      "title": "MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85431"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-85436",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "essential-moos",
      "cwe": "CWE-191",
      "title": "MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative UDP Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85436"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-85441",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-195",
      "title": "MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85441"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-85442",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-789",
      "title": "MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85442"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-85443",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-400",
      "title": "MOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85443"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-85444",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-125",
      "title": "MOOS-IvP through 24.8.1 Out-of-Bounds Read in isBraced, isQuoted and isChevroned",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85444"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-85445",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-789",
      "title": "MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85445"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-85446",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-407",
      "title": "MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85446"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-85447",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-770",
      "title": "MOOS-IvP through 24.8.1 pRealm Unbounded REALMCAST_REQ Subscription Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85447"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-85448",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-770",
      "title": "MOOS-IvP through 24.8.1 uFldShoreBroker Unbounded Community State Retention",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85448"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-85449",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-770",
      "title": "MOOS-IvP through 24.8.1 pMarineViewer Unbounded Memory Consumption via NODE_REPORT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85449"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-85450",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-770",
      "title": "MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85450"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-85452",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "ui-moos",
      "cwe": "CWE-787",
      "title": "MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85452"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-63219",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geonetwork",
      "product": "core-geonetwork",
      "cwe": "CWE-862",
      "title": "Unauthenticated file upload via missing authorization on formatter upload endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63219"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-64199",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "measX",
      "product": "DASYLab",
      "cwe": "CWE-125",
      "title": "Out Of Bounds Read outside the bounds of an allocated data structure when parsing a .DSB file in DASYLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64199"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-71963",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-78",
      "title": "Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71963"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-85223",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-340L",
      "cwe": "CWE-77",
      "title": "D-Link DNS-340L CGI dropbox.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85223"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-85237",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-307",
      "title": "Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85237"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-85388",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Worklenz",
      "product": "worklenz",
      "cwe": "CWE-89",
      "title": "Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85388"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-64195",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "measX",
      "product": "DASYLab",
      "cwe": "CWE-787",
      "title": "Out Of Bounds Write parsing a .DSB file in DASYLab due to lack of proper validation of user-supplied data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64195"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-64196",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "measX",
      "product": "DASYLab",
      "cwe": "CWE-787",
      "title": "Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64196"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-64197",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "measX",
      "product": "DASYLab",
      "cwe": "CWE-787",
      "title": "Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64197"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-64198",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "measX",
      "product": "DASYLab",
      "cwe": "CWE-125",
      "title": "Out Of Bounds Read in file handling when parsing a .DSB file in DASYLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64198"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-64200",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "measX",
      "product": "DASYLab",
      "cwe": "CWE-125",
      "title": "Out Of Bounds Read in during string conversionwhen parsing a .DSB file in DASYLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64200"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-65818",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Power Platform",
      "cwe": "CWE-918",
      "title": "Power Automate Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65818"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-67397",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-22",
      "title": "Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67397"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-69857",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Cosmos DB",
      "cwe": "CWE-639",
      "title": "Azure Cosmos DB Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69857"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-70178",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Fabric",
      "cwe": "CWE-862",
      "title": "Microsoft Fabric Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70178"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-85012",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "@amazon-codecatalyst/blueprints.blueprint",
      "cwe": "CWE-78",
      "title": "OS command injection in the Amazon CodeCatalyst blueprints SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85012"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-85222",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-340L",
      "cwe": "CWE-77",
      "title": "D-Link DNS-340L Add-On Center addon_center.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85222"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-85224",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320 ShareCenter",
      "cwe": "CWE-77",
      "title": "D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85224"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-85439",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-78",
      "title": "MOOS-IvP through 24.8.1 alogsplit Command Injection via Input Pathname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85439"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2025-12737",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Open Banking AM",
      "cwe": "CWE-78",
      "title": "Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12737"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-85179",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HumanSignal",
      "product": "label-studio",
      "cwe": "CWE-918",
      "title": "Label Studio through 1.23.0 SSRF via Unvalidated Webhook URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85179"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-84736",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse aeriOS",
      "cwe": "CWE-295",
      "title": "In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification. As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens. The issue has been addressed by enabling TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84736"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-85048",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85048"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-85178",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Helicone",
      "product": "helicone",
      "cwe": "CWE-639",
      "title": "Helicone Cross-Tenant Provider Key Disclosure via Missing Organization Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85178"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-85211",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HumanSignal",
      "product": "label-studio",
      "cwe": "CWE-639",
      "title": "Label Studio through 1.23.0 Cross-Organization Storage URI Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85211"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-44506",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "medplum",
      "product": "medplum",
      "cwe": "CWE-200",
      "title": "Medplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44506"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-63376",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BinaryMuse",
      "product": "toml-node",
      "cwe": "CWE-1321",
      "title": "toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63376"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-67398",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "WHMCS",
      "cwe": "CWE-862",
      "title": "Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67398"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-84757",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AresIT",
      "product": "WP Compress",
      "cwe": "CWE-862",
      "title": "WordPress WP Compress plugin <= 7.21.28 - Settings Change vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84757"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-84964",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-415",
      "title": "Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84964"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-78583",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78583"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-82302",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82302"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-84779",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sheikh Heera",
      "product": "Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents",
      "cwe": "CWE-862",
      "title": "WordPress Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84779"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-83959",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Substance 3D Sampler",
      "cwe": "CWE-122",
      "title": "Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83959"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-18167",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer AX55 v4",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow in TP-Link Archer AX55 v4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18167"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-55658",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Hive",
      "product": "gardens-v2",
      "cwe": "CWE-862",
      "title": "Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the permissionless claim()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55658"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-75033",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-639",
      "title": "Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75033"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-85168",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-78",
      "title": "n8n before 1.123.73 Remote Code Execution via Git Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85168"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-85182",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lenve",
      "product": "vhr",
      "cwe": "CWE-639",
      "title": "vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85182"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-85221",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-295",
      "title": "MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85221"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-85238",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-384",
      "title": "Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85238"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-6071",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "Arena",
      "cwe": "CWE-787",
      "title": "Code Execution Vulnerability in Arena®",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6071"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-8862",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Netezza Software",
      "cwe": "CWE-522",
      "title": "Vulnerabilities exists in IBM Netezza Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8862"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-33630",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "c-ares",
      "product": "c-ares",
      "cwe": "CWE-415",
      "title": "c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33630"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-48486",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signum-network",
      "product": "signum-node",
      "cwe": "CWE-190",
      "title": "Signum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary miner reward inflation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48486"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-77465",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BinaryMuse",
      "product": "toml-node",
      "cwe": "CWE-674",
      "title": "toml-node: Uncontrolled Recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77465"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-84776",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "malcare",
      "product": "MalCare Security",
      "cwe": "CWE-770",
      "title": "WordPress MalCare Security plugin <= 6.69 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84776"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-84778",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "migrateguru",
      "product": "Migrate Guru – Site Migration &amp; Cloning",
      "cwe": "CWE-770",
      "title": "WordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84778"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-84847",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brightvesseldev",
      "product": "Quick Event Manager",
      "cwe": "CWE-862",
      "title": "WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84847"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-85045",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85045"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-85124",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/http-proxy",
      "product": "@fastify/http-proxy",
      "cwe": "CWE-22",
      "title": "@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85124"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-85150",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85150"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-62906",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Discovery Studio",
      "cwe": "CWE-943",
      "title": "Microsoft Discovery Studio Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62906"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-75034",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-294",
      "title": "Rancher: SAML Assertion Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75034"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-84777",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Really Simple Plugins",
      "product": "Really Simple SSL",
      "cwe": "CWE-288",
      "title": "WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84777"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-85110",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG10",
      "cwe": "CWE-119",
      "title": "Tenda HG10 Boa Web Server formWlanSetup buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85110"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-15431",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Support Assistant",
      "cwe": "CWE-1220",
      "title": "HP Support Assistant – Potential Escalation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15431"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-85028",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-fpga",
      "cwe": "CWE-379",
      "title": "Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85028"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-84761",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LiteSpeed Technologies",
      "product": "LiteSpeed Cache",
      "cwe": "CWE-918",
      "title": "WordPress LiteSpeed Cache plugin <= 7.9 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84761"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-84773",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "作者: Shane Bishop",
      "product": "EWWW Image Optimizer",
      "cwe": "CWE-79",
      "title": "WordPress EWWW Image Optimizer plugin <= 8.7.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84773"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-85160",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-73",
      "title": "AVideo through c91b5975d CSRF and Path Traversal via stopLive.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85160"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-85165",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-95",
      "title": "n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85165"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-85166",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85166"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-85213",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "killbill",
      "product": "killbill",
      "cwe": "CWE-862",
      "title": "Kill Bill through 0.24.21 Missing Authorization on AdminResource Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85213"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-85214",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lenve",
      "product": "vhr",
      "cwe": "CWE-639",
      "title": "vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85214"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-53728",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "medplum",
      "product": "medplum",
      "cwe": "CWE-345",
      "title": "Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53728"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-75035",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-639",
      "title": "Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75035"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-78065",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-639",
      "title": "Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78065"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-81292",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ido Kobelkowsky",
      "product": "Simple Payment",
      "cwe": "CWE-79",
      "title": "WordPress Simple Payment plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81292"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-81295",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UnderConstructionPage",
      "product": "Under Construction",
      "cwe": "CWE-79",
      "title": "WordPress Under Construction plugin <= 5.82 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81295"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-81300",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silverplugins217",
      "product": "Calculation For Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress Calculation For Contact Form 7 plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81300"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-81773",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms File Uploads Extension",
      "cwe": "CWE-79",
      "title": "WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81773"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-81776",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "advanpix",
      "product": "WP QuickLaTeX",
      "cwe": "CWE-79",
      "title": "WordPress WP QuickLaTeX plugin <= 3.8.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81776"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-83961",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-287",
      "title": "ColdFusion | Improper Authentication (CWE-287)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83961"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-84756",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Lovers",
      "product": "WCFM Membership",
      "cwe": "CWE-266",
      "title": "WordPress WCFM Membership plugin <= 2.11.11 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84756"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-84763",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rometheme",
      "product": "RTMKit",
      "cwe": "CWE-79",
      "title": "WordPress RTMKit plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84763"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-84765",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "John Havlik",
      "product": "Breadcrumb NavXT",
      "cwe": "CWE-79",
      "title": "WordPress Breadcrumb NavXT plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84765"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-84812",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "BP Better Messages",
      "cwe": "CWE-79",
      "title": "WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84812"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-84836",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kirillbdev",
      "product": "WC Ukraine Shipping",
      "cwe": "CWE-639",
      "title": "WordPress WC Ukraine Shipping plugin <= 1.22.3 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84836"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-84848",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brightvesseldev",
      "product": "Quick Event Manager",
      "cwe": "CWE-79",
      "title": "WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84848"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-84971",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "libmongocrypt",
      "cwe": "CWE-617",
      "title": "Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84971"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-84989",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntop",
      "product": "ntopng",
      "cwe": "CWE-862",
      "title": "ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84989"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-85162",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "AVideo through c91b5975d CSRF via saveLive.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85162"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-85163",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-918",
      "title": "AVideo Server-Side Request Forgery via epg_link parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85163"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-85164",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-918",
      "title": "WWBN AVideo Server-Side Request Forgery via set_api_userImages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85164"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-85170",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-20",
      "title": "n8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85170"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-85171",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-532",
      "title": "n8n before 1.123.73 Credential Exposure via Error Logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85171"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-85239",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-20",
      "title": "MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85239"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-85389",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Worklenz",
      "product": "worklenz",
      "cwe": "CWE-639",
      "title": "Worklenz before 3.0.0 Authorization Bypass on Task-Scoped Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85389"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-85390",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bluewave-labs",
      "product": "Checkmate",
      "cwe": "CWE-862",
      "title": "Checkmate through 3.11.0 Missing Authorization on Maintenance Window, Notification, and Check Deletion Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85390"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-85395",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unopim",
      "product": "unopim",
      "cwe": "CWE-862",
      "title": "UnoPim before 2.1.3 Missing Authorization on Integration Management Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85395"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-85451",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-798",
      "title": "MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphrase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85451"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-71220",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7",
      "cwe": "CWE-787",
      "title": "Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71220"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-71221",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7",
      "cwe": "CWE-787",
      "title": "Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71221"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-79679",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "B&R Industrial Automation GmbH",
      "product": "mapp Services",
      "cwe": "CWE-1391",
      "title": "Use of Weak Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79679"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-15933",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OptimiDoc",
      "product": "OptimiDoc Server",
      "cwe": "CWE-256",
      "title": "Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15933"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-84968",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "PHP Driver",
      "cwe": "CWE-125",
      "title": "Heap out-of-bounds read via corrupt nested BSON in field path error message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84968"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-85062",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omgovich",
      "product": "colord",
      "cwe": "CWE-1333",
      "title": "Colord: Slow rejection of oversized malformed color strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85062"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-85063",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adaltas",
      "product": "node-csv",
      "cwe": "CWE-1321",
      "title": "node-csv: Prototype replacement still reachable via columns path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85063"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-85105",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-285",
      "title": "NousResearch hermes-agent Session Management s71.py _sess_nowait authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85105"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-85156",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Broken Access Control via Channel Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85156"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-85157",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Broken Access Control via feed/index.php program_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85157"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-85242",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lookyloo",
      "product": "PlaywrightCapture",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery via Favicon Redirect to Local Network Resources in PlaywrightCapture",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85242"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-82525",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exterro",
      "product": "FTK Imager",
      "cwe": "CWE-611",
      "title": "Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82525"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-85456",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moos-ivp",
      "product": "moos-ivp",
      "cwe": "CWE-22",
      "title": "MOOS-IvP through 24.8.1 alog Splitting Path Traversal on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85456"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-82918",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Keyence Corporation",
      "product": "XG-X VisionTerminal",
      "cwe": "CWE-611",
      "title": "XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82918"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-9745",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Netezza Software",
      "cwe": "CWE-283",
      "title": "Vulnerabilities exists in IBM Netezza Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9745"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-49455",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wakujs",
      "product": "waku",
      "cwe": "CWE-352",
      "title": "Waku: Cross-Origin CSRF on RSC Server Action Dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49455"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-75602",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenListTeam",
      "product": "OpenList",
      "cwe": "CWE-22",
      "title": "OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75602"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-81281",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silverks",
      "product": "Graphene",
      "cwe": "CWE-79",
      "title": "WordPress Graphene theme <= 2.9.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81281"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-81282",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Product Variations Swatches for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81282"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-82299",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82299"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-84215",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "Timetics",
      "cwe": "CWE-862",
      "title": "WordPress Timetics plugin <= 1.0.61 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84215"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-84754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "WPFunnels",
      "cwe": "CWE-862",
      "title": "WordPress WPFunnels plugin <= 3.12.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84754"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-84755",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "Mail Mint",
      "cwe": "CWE-862",
      "title": "WordPress Mail Mint plugin <= 1.31.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84755"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-84758",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-862",
      "title": "WordPress Business Directory plugin <= 6.4.26 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84758"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-84769",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-639",
      "title": "WordPress Business Directory plugin <= 6.4.26 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84769"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-84849",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brightvesseldev",
      "product": "Pre-Orders for WooCommerce",
      "cwe": "CWE-290",
      "title": "WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84849"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-85302",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPKoi WordPress Themes",
      "product": "WPKoi Templates for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress WPKoi Templates for Elementor plugin <= 3.7.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85302"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-85303",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "Booking and Rental Manager",
      "cwe": "CWE-79",
      "title": "WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85303"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-85306",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cascadia Web Services",
      "product": "MountDev AI MCP Connector for WordPress",
      "cwe": "CWE-862",
      "title": "WordPress MountDev AI MCP Connector for WordPress plugin <= 1.6.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85306"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-82521",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "domainaware",
      "product": "parsedmarc",
      "cwe": "CWE-22",
      "title": "parsedmarc 9.0.6 < 11.0.1 Path Traversal via Forensic Report Subject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82521"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-84963",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-681",
      "title": "Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84963"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-84969",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-787",
      "title": "Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84969"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-85167",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-943",
      "title": "n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85167"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-19795",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Qiskit SDK",
      "cwe": "CWE-502",
      "title": "Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19795"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-71429",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uhop",
      "product": "stream-json",
      "cwe": "CWE-407",
      "title": "stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71429"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-18330",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer AX55 v4",
      "cwe": "CWE-321",
      "title": "Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18330"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-71403",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-639",
      "title": "Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71403"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-84774",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VeronaLabs",
      "product": "WP Statistics",
      "cwe": "CWE-79",
      "title": "WordPress WP Statistics plugin <= 14.16.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84774"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-85227",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAttachedAttributes Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85227"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-3416",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-330",
      "title": "Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3416"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-9036",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Netezza Software",
      "cwe": "CWE-295",
      "title": "Vulnerabilities exists in IBM Netezza Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9036"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-84185",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-347",
      "title": "Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84185"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-84766",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Manage Ninja",
      "product": "FluentBooking Pro",
      "cwe": "CWE-290",
      "title": "WordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84766"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-84965",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-190",
      "title": "Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84965"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-84966",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C++ Driver",
      "cwe": "CWE-681",
      "title": "BSON element injection via NUL-embedded document keys in builder append",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84966"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-84970",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C++ Driver",
      "cwe": "CWE-681",
      "title": "Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84970"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-84815",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kriesi",
      "product": "Enfold",
      "cwe": "CWE-79",
      "title": "WordPress Enfold theme <= 8.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84815"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-84962",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "libmongocrypt",
      "cwe": "CWE-93",
      "title": "Authenticated KMS request forgery via CRLF injection in GCP key identifier strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84962"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-85137",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-74",
      "title": "SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85137"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-85138",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SeaCMS",
      "cwe": "CWE-74",
      "title": "SeaCMS WeChat index.php addslashes sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85138"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-85187",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85187"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-85208",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-284",
      "title": "itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85208"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-85225",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Doctor Appointment System",
      "cwe": "CWE-74",
      "title": "code-projects Doctor Appointment System patient_login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85225"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-85378",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-285",
      "title": "light0011 cms Chapter Controller ChapterController.class.php _initialize authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85378"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-85305",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEOPress",
      "product": "SEOPress",
      "cwe": "CWE-918",
      "title": "WordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85305"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-9736",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Netezza Software",
      "cwe": "CWE-117",
      "title": "Vulnerabilities exists in IBM Netezza Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9736"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-9744",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Netezza Software",
      "cwe": "CWE-297",
      "title": "Vulnerabilities exists in IBM Netezza Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9744"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-50554",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "enchant97",
      "product": "note-mark",
      "cwe": "CWE-200",
      "title": "Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-mark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50554"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-71222",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7",
      "cwe": "CWE-125",
      "title": "Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71222"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-75036",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Fleet",
      "cwe": "CWE-918",
      "title": "Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75036"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-78000",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j2commerce.com",
      "product": "J2Store extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78000"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-82023",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "LearnPress",
      "cwe": "CWE-863",
      "title": "LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82023"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-84762",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "WP EasyPay",
      "cwe": "CWE-472",
      "title": "WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84762"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-84767",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "BookIt",
      "cwe": "CWE-345",
      "title": "WordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84767"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-85106",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-918",
      "title": "NousResearch hermes-agent Link Title Fetch index.tsx fetchLinkTitle server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85106"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-85107",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-400",
      "title": "NousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85107"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-85135",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "ILIAS",
      "cwe": "CWE-284",
      "title": "ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85135"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-85158",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo Reflected XSS via videoEmbeded.php link parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85158"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-85159",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo Reflected XSS via cancelUri in userLogin.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85159"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-85161",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "AVideo removePoster.php Cross-Site Request Forgery File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85161"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-85172",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n before 2.34.1 SSRF via Request Helper URI Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85172"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-85173",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 2.36.2 Missing Authorization via Insights API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85173"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-85177",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crmeb",
      "product": "CRMEB",
      "cwe": "CWE-639",
      "title": "CRMEB through 6.0.0 Unauthorized Message Modification via edit_message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85177"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-85205",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85205"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-85210",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oppia",
      "product": "oppia",
      "cwe": "CWE-862",
      "title": "Oppia through 3.5.2 Missing Authorization on AdminRoleHandler GET",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85210"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-85226",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-862",
      "title": "MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Correlations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85226"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-85230",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-20",
      "title": "MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85230"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-85241",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpecterOps",
      "product": "BloodHound",
      "cwe": "CWE-266",
      "title": "SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85241"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-85304",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-862",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.17 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85304"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-85307",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kevin Pirnie",
      "product": "KP Agent Ready",
      "cwe": "CWE-201",
      "title": "WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85307"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-85308",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "SureForms",
      "cwe": "CWE-639",
      "title": "WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85308"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-85309",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Supsystic",
      "product": "Ultimate Maps by Supsystic",
      "cwe": "CWE-862",
      "title": "WordPress Ultimate Maps by Supsystic plugin <= 1.5.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85309"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-85392",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Peppermint-Lab",
      "product": "peppermint",
      "cwe": "CWE-639",
      "title": "Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85392"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-85453",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-79",
      "title": "MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85453"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-85454",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themoos",
      "product": "core-moos",
      "cwe": "CWE-193",
      "title": "MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85454"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-53720",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetperch",
      "product": "pymonocypher",
      "cwe": "CWE-122",
      "title": "pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53720"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-56126",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netgate",
      "product": "pfSense Plus",
      "cwe": "CWE-79",
      "title": "pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56126"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-56127",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netgate",
      "product": "pfSense Plus",
      "cwe": "CWE-79",
      "title": "pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56127"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-56128",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netgate",
      "product": "pfSense Plus",
      "cwe": "CWE-79",
      "title": "pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56128"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-82024",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "LearnPress",
      "cwe": "CWE-79",
      "title": "LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82024"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-84967",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB for VS Code",
      "cwe": "CWE-78",
      "title": "Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84967"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-35160",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "SmartFabric OS10 Software",
      "cwe": "CWE-78",
      "title": "Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35160"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-63694",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "SmartFabric OS10",
      "cwe": "CWE-77",
      "title": "Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63694"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-71219",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7",
      "cwe": "CWE-770",
      "title": "Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71219"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-71224",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7",
      "cwe": "CWE-770",
      "title": "Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71224"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-49509",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Opensource",
      "product": "rLottie",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers. This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49509"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-78593",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code in Kibana Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78593"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-78595",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78595"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-78596",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78596"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-82298",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82298"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-49456",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wakujs",
      "product": "waku",
      "cwe": "CWE-601",
      "title": "Waku: Open Redirect via `unstable_redirect` Helper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49456"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-85052",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85052"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-85186",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-284",
      "title": "itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85186"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-85458",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xpdf",
      "product": "Xpdf",
      "cwe": "CWE-369",
      "title": "Divide-by-zero in Xpdf 4.06 due to zero-height Type 3 glyph",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85458"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-85207",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Medicine Delivery System",
      "cwe": "CWE-79",
      "title": "itsourcecode Online Medicine Delivery System index.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85207"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-85043",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "title": "Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85043"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-85044",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-672",
      "title": "Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85044"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10522",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10522 (Unknown MemberHero). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14216 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19586",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19586 (TP-Link Systems Inc. ER7212PC v2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19722",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19722 (Unknown WPvivid — Backup, Migration & Staging). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49869",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49869 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62911",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62911 (Microsoft Exchange Server 2016 Cumulative Update 23). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63293 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66401",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66401 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66418",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66418 (tugcantopaloglu openclaw-dashboard). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66421",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66421 (tugcantopaloglu openclaw-dashboard). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67291",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67291 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67322",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67322 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67323",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67323 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67324",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67324 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67325",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67325 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73483",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73483 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73484",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73484 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73485",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73485 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73486 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73487 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73488 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73619",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73619 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73620 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73621",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73621 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73622",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73622 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73623",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73623 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73625 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75134",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75134 (SEOWriting). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76217",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76217 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76218",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76218 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76219",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76219 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76220",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76220 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77790",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77790 (Unknown RegistrationMagic). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82524",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-83613",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-83613 (xmldom). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84110",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84110 (Releasit COD Form & Upsells). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84127",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84127 (Mozilla Firefox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84287",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84287 (NousResearch hermes-agent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84423",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84423 (Casdoor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84427",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84427 (zhayujie CowAgent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84437",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84437 (OpenCart). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84441",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84441 (Piwigo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84832",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84832 (SEPPmail AG SEPPmail Secure Email Gateway (SEG)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84833 (ntegrals openbrowser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84839",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84839 (tsi-coop tsi-dpdp-cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84856",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84856 (rowboatlabs rowboat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84857",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84857 (sigoden aichat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-9586",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-9586 (Sangoma Switchvox SMB Edition). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-64849",
      "detail": "DUE DATE PASSED — CVE-2026-64849 (mlflow). CISA remediation deadline was September 2, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-12107",
      "detail": "RESCORED — CVE-2025-12107 (WSO2 Identity Server). CVSS 8.4 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-11835",
      "detail": "RESCORED — CVE-2026-11835 (Caliptra Core ROM). CVSS 5.6 → 5.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-64631",
      "detail": "RESCORED — CVE-2026-64631 (Veeam ONE). CVSS 8.5 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72680",
      "detail": "RESCORED — CVE-2026-72680 (Elastic Kibana). CVSS 6.5 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72681",
      "detail": "RESCORED — CVE-2026-72681 (Elastic Kibana). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7326",
      "detail": "RESCORED — CVE-2026-7326 (Progress Software Corporation MarkLogic Server). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84136",
      "detail": "RESCORED — CVE-2026-84136 (Mozilla Firefox). CVSS 9.8 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84137",
      "detail": "RESCORED — CVE-2026-84137 (Mozilla Firefox). CVSS 9.8 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84138",
      "detail": "RESCORED — CVE-2026-84138 (Mozilla Firefox). CVSS 7.5 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84139",
      "detail": "RESCORED — CVE-2026-84139 (Mozilla Firefox). CVSS 9.8 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84885",
      "detail": "RESCORED — CVE-2026-84885 (simular-ai Agent-S). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84886",
      "detail": "RESCORED — CVE-2026-84886 (simular-ai Agent-S). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84887",
      "detail": "RESCORED — CVE-2026-84887 (simular-ai Agent-S). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84888",
      "detail": "RESCORED — CVE-2026-84888 (RightNow-AI OpenFang). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-19582",
      "detail": "REJECTED — CVE-2026-19582 (Red Hat Migration Toolkit for Containers). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-76848",
      "detail": "REJECTED — CVE-2026-76848 (typeorm). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16493",
      "detail": "PATCH SHIPPED — CVE-2026-16493 (Red Hat Satellite 6.17 for RHEL 9). Fixed in Red Hat Satellite 6.17 for RHEL 9 1:2.16.19-1.el9sat."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18255",
      "detail": "PATCH SHIPPED — CVE-2026-18255 (Red Hat Quay 3.15). Fixed in Red Hat Quay 3.15 1788191755."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-78408",
      "detail": "PATCH SHIPPED — CVE-2026-78408 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.42.2-3.4.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-78409",
      "detail": "PATCH SHIPPED — CVE-2026-78409 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.42.2-3.4.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-78410",
      "detail": "PATCH SHIPPED — CVE-2026-78410 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.42.2-3.4.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-82451",
      "detail": "PATCH SHIPPED — CVE-2026-82451 (getformwork Formwork). Fixed in Formwork 2.3.11."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64064",
      "detail": "ENRICHED — CVE-2026-64064 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64065",
      "detail": "ENRICHED — CVE-2026-64065 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64070",
      "detail": "ENRICHED — CVE-2026-64070 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64071",
      "detail": "ENRICHED — CVE-2026-64071 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64072",
      "detail": "ENRICHED — CVE-2026-64072 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64075",
      "detail": "ENRICHED — CVE-2026-64075 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64079",
      "detail": "ENRICHED — CVE-2026-64079 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64083",
      "detail": "ENRICHED — CVE-2026-64083 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64085",
      "detail": "ENRICHED — CVE-2026-64085 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64087",
      "detail": "ENRICHED — CVE-2026-64087 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64301",
      "detail": "ENRICHED — CVE-2026-64301 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64302",
      "detail": "ENRICHED — CVE-2026-64302 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64305",
      "detail": "ENRICHED — CVE-2026-64305 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64306",
      "detail": "ENRICHED — CVE-2026-64306 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64314",
      "detail": "ENRICHED — CVE-2026-64314 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64316",
      "detail": "ENRICHED — CVE-2026-64316 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64331",
      "detail": "ENRICHED — CVE-2026-64331 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64332",
      "detail": "ENRICHED — CVE-2026-64332 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64334",
      "detail": "ENRICHED — CVE-2026-64334 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64335",
      "detail": "ENRICHED — CVE-2026-64335 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64336",
      "detail": "ENRICHED — CVE-2026-64336 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64337",
      "detail": "ENRICHED — CVE-2026-64337 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64338",
      "detail": "ENRICHED — CVE-2026-64338 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64339",
      "detail": "ENRICHED — CVE-2026-64339 (Linux). Received CVSS 7.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64340",
      "detail": "ENRICHED — CVE-2026-64340 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64341",
      "detail": "ENRICHED — CVE-2026-64341 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64342",
      "detail": "ENRICHED — CVE-2026-64342 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64343",
      "detail": "ENRICHED — CVE-2026-64343 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64344",
      "detail": "ENRICHED — CVE-2026-64344 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64345",
      "detail": "ENRICHED — CVE-2026-64345 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64346",
      "detail": "ENRICHED — CVE-2026-64346 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64347",
      "detail": "ENRICHED — CVE-2026-64347 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64348",
      "detail": "ENRICHED — CVE-2026-64348 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64349",
      "detail": "ENRICHED — CVE-2026-64349 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64350",
      "detail": "ENRICHED — CVE-2026-64350 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64351",
      "detail": "ENRICHED — CVE-2026-64351 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64352",
      "detail": "ENRICHED — CVE-2026-64352 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64353",
      "detail": "ENRICHED — CVE-2026-64353 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64429",
      "detail": "ENRICHED — CVE-2026-64429 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64433",
      "detail": "ENRICHED — CVE-2026-64433 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64446",
      "detail": "ENRICHED — CVE-2026-64446 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64451",
      "detail": "ENRICHED — CVE-2026-64451 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64453",
      "detail": "ENRICHED — CVE-2026-64453 (Linux). Received CVSS 7.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
