{
  "day": "2026-09-04",
  "boundary": "UTC calendar day",
  "published_count": 563,
  "by_severity": {
    "CRITICAL": 44,
    "HIGH": 143,
    "MEDIUM": 162,
    "LOW": 18
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 196,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-62928",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01218,
      "epss_percentile": 0.6661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xing Inc.",
      "product": "XING CPTrans-ME-X",
      "cwe": "CWE-78",
      "title": "XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62928"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-82923",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00826,
      "epss_percentile": 0.55001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Website Builder (GitHub build)",
      "cwe": "CWE-862",
      "title": "AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82923"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-85184",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00544,
      "epss_percentile": 0.43649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/middie",
      "product": "@fastify/middie",
      "cwe": "CWE-436",
      "title": "@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85184"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-85540",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00543,
      "epss_percentile": 0.43599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interinfo",
      "product": "DreamMaker",
      "cwe": "CWE-89",
      "title": "Interinfo｜DreamMaker - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85540"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-76169",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00529,
      "epss_percentile": 0.42765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify",
      "product": "fastify",
      "cwe": "CWE-288",
      "title": "fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76169"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-84469",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00519,
      "epss_percentile": 0.42202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify",
      "product": "fastify",
      "cwe": "CWE-20",
      "title": "fastify vulnerable to request validation bypass via skipped boolean false schemas",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84469"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-11613",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00455,
      "epss_percentile": 0.37974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Divi Engine",
      "product": "Divi Ajax Filter",
      "cwe": "CWE-98",
      "title": "Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11613"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-85504",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeIPMI",
      "product": "FreeIPMI",
      "cwe": "CWE-121",
      "title": "FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85504"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-85506",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeIPMI",
      "product": "FreeIPMI",
      "cwe": "CWE-121",
      "title": "ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85506"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-85507",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeIPMI",
      "product": "FreeIPMI",
      "cwe": "CWE-121",
      "title": "ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85507"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-85508",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeIPMI",
      "product": "FreeIPMI",
      "cwe": "CWE-121",
      "title": "ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85508"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-85509",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeIPMI",
      "product": "FreeIPMI",
      "cwe": "CWE-121",
      "title": "FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85509"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-84504",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.3176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify",
      "product": "fastify",
      "cwe": "CWE-20",
      "title": "fastify vulnerable to request body replacement via an async validation result collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84504"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-13148",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0038,
      "epss_percentile": 0.31118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softing",
      "product": "smartLink HW-PN",
      "cwe": "CWE-401",
      "title": "Memory leak in scan method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13148"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-85146",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.27942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lightstar",
      "product": "SmartIT Desktop Manager",
      "cwe": "CWE-798",
      "title": "Lightstar｜SmartIT Desktop Manager - Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85146"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-85148",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.27942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lightstar",
      "product": "SmartIT Desktop Manager",
      "cwe": "CWE-798",
      "title": "Lightstar｜SmartIT Desktop Manager - Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85148"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-85547",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery via Attacker-Controlled REST Detection in MISP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85547"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-85505",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeIPMI",
      "product": "FreeIPMI",
      "cwe": "CWE-125",
      "title": "ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85505"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-85409",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00339,
      "epss_percentile": 0.2674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Quality Management",
      "cwe": "CWE-22",
      "title": "Eleveo Quality Management Questionnaire Service QuestionnaireService.runDataExportNow path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85409"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-85381",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-285",
      "title": "light0011 cms Chapter Controller ChapterController.class.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85381"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-85538",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85538"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-15354",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.003,
      "epss_percentile": 0.22207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mauro Cassani",
      "product": "ACPT (Premium)",
      "cwe": "CWE-269",
      "title": "ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15354"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-69657",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xing Inc.",
      "product": "XING CPTrans-ME-X",
      "cwe": "CWE-1393",
      "title": "XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69657"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-70403",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xing Inc.",
      "product": "XING CPTrans-ME-X",
      "cwe": "CWE-259",
      "title": "XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70403"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-85380",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.20983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-918",
      "title": "light0011 cms UEditor controller.php catchimage server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85380"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-85382",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85382"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-81666",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81666"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-85407",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.18983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Quality Management",
      "cwe": "CWE-404",
      "title": "Eleveo Quality Management Conversation events denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85407"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-85402",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.18718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Doctor Appointment System",
      "cwe": "CWE-74",
      "title": "code-projects Doctor Appointment System booking.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85402"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-85379",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-74",
      "title": "light0011 cms Query Builder ChapterController.class.php searchChapter sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85379"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-85397",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hospital Information System",
      "cwe": "CWE-74",
      "title": "code-projects Hospital Information System addReq.php findBySearch sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85397"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-85398",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hospital Information System",
      "cwe": "CWE-74",
      "title": "code-projects Hospital Information System viewReq.php viewReq sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85398"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-85399",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hospital Information System",
      "cwe": "CWE-74",
      "title": "code-projects Hospital Information System PrespController.php getSinglePresp sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85399"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-85403",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.1792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Doctor Appointment System",
      "cwe": "CWE-74",
      "title": "code-projects Doctor Appointment System contactus.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85403"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-85541",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interinfo",
      "product": "DreamMaker",
      "cwe": "CWE-79",
      "title": "Interinfo｜DreamMaker - Reflected Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85541"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-66840",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xing Inc.",
      "product": "XING CPTrans-ME-X",
      "cwe": "CWE-497",
      "title": "XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66840"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-85401",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Dolibarr",
      "cwe": "CWE-266",
      "title": "Dolibarr Legacy File Manager config.inc.php access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85401"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-85149",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lightstar",
      "product": "SmartIT Desktop Manager",
      "cwe": "CWE-798",
      "title": "Lightstar｜SmartIT Desktop Manager - Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85149"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-57777",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Automattic",
      "product": "WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57777"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-85094",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canva",
      "product": "Canva",
      "cwe": "CWE-212",
      "title": "The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85094"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-85408",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00233,
      "epss_percentile": 0.14073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Quality Management",
      "cwe": "CWE-913",
      "title": "Eleveo Quality Management Conversation events dynamically-determined object attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85408"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-27086",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.12971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xtemos",
      "product": "WoodMart",
      "cwe": "CWE-79",
      "title": "WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27086"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-85085",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00221,
      "epss_percentile": 0.12536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canva",
      "product": "Canva",
      "cwe": "CWE-940",
      "title": "The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85085"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-85533",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-862",
      "title": "MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85533"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-75754",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00215,
      "epss_percentile": 0.11783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Control Center Enterprise (ACC)",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75754"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-81665",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81665"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-80180",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.1078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-79",
      "title": "Apache Allura: Stored XSS via markdown HTML processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80180"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-80181",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.10628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-918",
      "title": "Apache Allura: Server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80181"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-85147",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lightstar",
      "product": "SmartIT Desktop Manager",
      "cwe": "CWE-284",
      "title": "Lightstar｜SmartIT Desktop Manager - Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85147"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-81270",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.09814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-200",
      "title": "Apache Allura: Information exposure via search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81270"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-85383",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System inv_del.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85383"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-85546",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-352",
      "title": "MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85546"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-85405",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.0878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-79",
      "title": "Eleveo Call Recording Software roleAddAction.do cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85405"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-85406",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.08781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Quality Management",
      "cwe": "CWE-79",
      "title": "Eleveo Quality Management Conversation Review cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85406"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-80190",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Allura",
      "cwe": "CWE-79",
      "title": "Apache Allura: Stored XSS via code repositories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80190"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-27432",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sc Internet Vivoo",
      "product": "WP Rentals",
      "cwe": "CWE-639",
      "title": "WordPress WP Rentals theme < 3.16.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27432"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-85197",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85197"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-85528",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.07809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake JDBC Driver",
      "cwe": "CWE-20",
      "title": "Snowflake JDBC Driver auto-configuration account validation permits credential redirection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85528"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-32480",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Lovers",
      "product": "WCFM Membership",
      "cwe": "CWE-862",
      "title": "WordPress WCFM Membership plugin <= 2.11.11 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32480"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-85311",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kings Plugins",
      "product": "MarketKing",
      "cwe": "CWE-862",
      "title": "WordPress MarketKing plugin <= 2.1.60 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85311"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-19224",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hummingbird Performance",
      "cwe": "CWE-94",
      "title": "Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19224"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-84043",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ePayco Payment Gateway for WooCommerce",
      "cwe": "CWE-345",
      "title": "ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84043"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-84044",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Restaurant Menu and Food Ordering",
      "cwe": null,
      "title": "Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84044"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-82186",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPLP Cookie Consent",
      "cwe": "CWE-89",
      "title": "WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82186"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-85229",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0016,
      "epss_percentile": 0.05482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache SkyWalking",
      "cwe": "CWE-79",
      "title": "Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85229"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-82193",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPvivid — Backup, Migration & Staging",
      "cwe": "CWE-22",
      "title": "WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup Directory via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82193"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-81302",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JAL Information Technology Co., Ltd.",
      "product": "PALLET CONTROL",
      "cwe": "CWE-276",
      "title": "PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81302"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-81347",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-73",
      "title": "Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81347"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-17517",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Content Views",
      "cwe": "CWE-200",
      "title": "Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17517"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-79631",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPFunnels",
      "cwe": "CWE-200",
      "title": "WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Log Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79631"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-15937",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-295",
      "title": "Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15937"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-74853",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Pods",
      "cwe": "CWE-552",
      "title": "Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74853"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-82194",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPvivid — Backup, Migration & Staging",
      "cwe": "CWE-73",
      "title": "WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82194"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-84146",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Xpro Addons — 140+ Widgets for Elementor",
      "cwe": "CWE-200",
      "title": "Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84146"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-45200",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.03593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-416",
      "title": "GPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by _EncodeAllocationFlags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45200"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2025-15691",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPFunnels",
      "cwe": "CWE-863",
      "title": "WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15691"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-79630",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPFunnels",
      "cwe": "CWE-639",
      "title": "WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79630"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-79632",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPFunnels",
      "cwe": "CWE-862",
      "title": "WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79632"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-16281",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Classified Listing",
      "cwe": "CWE-639",
      "title": "Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16281"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-80438",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ninja Forms",
      "cwe": "CWE-284",
      "title": "Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and Sensitive Information Disclosure via Abilities REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80438"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-84066",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-862",
      "title": "Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84066"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-45197",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00112,
      "epss_percentile": 0.01479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-367",
      "title": "GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45197"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-6217",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pik Online Software Solutions Inc.",
      "product": "Pik Online Portal",
      "cwe": "CWE-759",
      "title": "Information Disclosure in Pik Online Software's Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6217"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-71216",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00109,
      "epss_percentile": 0.01353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache SkyWalking",
      "cwe": "CWE-319",
      "title": "Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71216"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-85525",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00105,
      "epss_percentile": 0.01161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake Connector for Python",
      "cwe": "CWE-295",
      "title": "Improper OCSP response validation in Snowflake drivers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85525"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-18658",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Operational Decision Manager",
      "cwe": "CWE-89",
      "title": "IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18658"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-31020",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulnerability that can be exploited to achieve full remote code execution (RCE).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31020"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-75430",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75430"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-19274",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Observability with Instana (Agent)",
      "cwe": "CWE-284",
      "title": "IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19274"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-52777",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-352",
      "title": "YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52777"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-75925",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IXON",
      "product": "IXON VPN Client",
      "cwe": "CWE-93",
      "title": "IXON VPN Client CRLF Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75925"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-44402",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Voltronic Power",
      "product": "SNMP Web Pro",
      "cwe": "CWE-434",
      "title": "Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44402"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-85595",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-287",
      "title": "Traefik before v2.11.55 Authentication Bypass via digestAuth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85595"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-85602",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-807",
      "title": "Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85602"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-85661",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haris-musa",
      "product": "excel-mcp-server",
      "cwe": "CWE-22",
      "title": "excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85661"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-85663",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aimhubio",
      "product": "aim",
      "cwe": "CWE-306",
      "title": "Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85663"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-85667",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamWiseFlow",
      "product": "xiaobei",
      "cwe": "CWE-306",
      "title": "xiaobei through 5.5.2 Unauthenticated Webhook Message Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85667"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-85672",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getomni-ai",
      "product": "zerox",
      "cwe": "CWE-78",
      "title": "zerox 1.1.20 OS Command Injection via Document URL File Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85672"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-85688",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TEN-framework",
      "product": "ten-framework",
      "cwe": "CWE-306",
      "title": "TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85688"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-85695",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lm-sys",
      "product": "FastChat",
      "cwe": "CWE-306",
      "title": "FastChat Unauthenticated Worker Registration SSRF and Model Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85695"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-85696",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenTalker",
      "product": "SadTalker",
      "cwe": "CWE-78",
      "title": "SadTalker OS Command Injection via Audio Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85696"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-9317",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NangoHQ",
      "product": "nango",
      "cwe": "CWE-306",
      "title": "Nango < 0.71.6 Missing Authentication RCE via runner tRPC server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9317"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-85614",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-918",
      "title": "OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85614"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-85620",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crystaldba",
      "product": "postgres-mcp",
      "cwe": "CWE-863",
      "title": "Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85620"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-85625",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crcn",
      "product": "sift.js",
      "cwe": "CWE-1321",
      "title": "sift 17.1.3 Prototype Pollution Remote Code Execution via $where",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85625"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-85660",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MladenSU",
      "product": "cli-mcp-server",
      "cwe": "CWE-78",
      "title": "cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85660"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-85694",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lavague-ai",
      "product": "LaVague",
      "cwe": "CWE-94",
      "title": "LaVague 0.2.35 Remote Code Execution via eval extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85694"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-52766",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-276",
      "title": "YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52766"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-75160",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75160"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-75431",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-321",
      "title": "PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75431"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-78327",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "Network Security Manager (NSM)",
      "cwe": "CWE-78",
      "title": "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78327"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-78328",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "Network Security Manager (NSM)",
      "cwe": "CWE-862",
      "title": "A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78328"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-81939",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicWall",
      "product": "Network Security Manager (NSM)",
      "cwe": "CWE-22",
      "title": "A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81939"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-48019",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laravel",
      "product": "framework",
      "cwe": "CWE-93",
      "title": "CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48019"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-18198",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TAC Information Services Internal and External Trade Inc.",
      "product": "GOLDENHORN ONEIT",
      "cwe": "CWE-89",
      "title": "SQL Injection in TAC Information's GoldenHorn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18198"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-18486",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "ContextForge MCP Gateway",
      "cwe": "CWE-200",
      "title": "IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18486"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-19298",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19298"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-52775",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki Authenticated SQL Injection in ReactionManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52775"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-57161",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-121",
      "title": "PJSIP: Stack overflow handling Service-Route headers in a registration response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57161"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-57162",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-121",
      "title": "PJSIP: Stack overflow parsing SDP a=crypto attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57162"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-57163",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-121",
      "title": "PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57163"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-85684",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datalab-to",
      "product": "marker",
      "cwe": "CWE-73",
      "title": "marker through 2.0.0 Path Traversal via upload filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85684"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-46636",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twigphp",
      "product": "Twig",
      "cwe": "CWE-1336",
      "title": "Twig: Sandbox method allowlist bypass via `Markup` subclass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46636"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-53758",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-79",
      "title": "Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53758"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-77393",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inductive Automation",
      "product": "Ignition",
      "cwe": "CWE-276",
      "title": "Inductive Automation Ignition Incorrect Default Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77393"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-79707",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Agent Development Kit (ADK)",
      "cwe": "CWE-22",
      "title": "Arbitrary File Read in Google Agent Development Kit (ADK)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79707"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-82538",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ILIAS-eLearning e.V.",
      "product": "ILIAS",
      "cwe": "CWE-89",
      "title": "ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82538"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-85581",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-770",
      "title": "SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85581"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-85584",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-770",
      "title": "SiYuan before v3.8.2 Denial of Service via Auth Throttle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85584"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-85585",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-400",
      "title": "SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85585"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-85604",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav before 2.0.19 Remote Code Execution via sort filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85604"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-85606",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "firecrawl",
      "product": "firecrawl-mcp-server",
      "cwe": "CWE-22",
      "title": "firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85606"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-85607",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blinkospace",
      "product": "blinko",
      "cwe": "CWE-639",
      "title": "Blinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85607"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-85608",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Evil0ctal",
      "product": "Douyin_TikTok_Download_API",
      "cwe": "CWE-918",
      "title": "Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85608"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-85610",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-94",
      "title": "OpenPanel before 2.3.0 Remote Code Execution via chart formulas",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85610"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-85612",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-918",
      "title": "OpenPanel before 2.3.0 SSRF via favicon and og endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85612"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-85617",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-639",
      "title": "snipe-it before 8.6.3 Authorization Bypass via Bulk Delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85617"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-85623",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aaif-goose",
      "product": "goose",
      "cwe": "CWE-94",
      "title": "goose 1.37.0 Arbitrary Command Execution via Recipe Extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85623"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-85626",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyanheads",
      "product": "git-mcp-server",
      "cwe": "CWE-88",
      "title": "git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85626"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-85664",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chroma-core",
      "product": "chroma",
      "cwe": "CWE-770",
      "title": "Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85664"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-85666",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ogx-ai",
      "product": "ogx",
      "cwe": "CWE-918",
      "title": "ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85666"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-85668",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xorbitsai",
      "product": "inference",
      "cwe": "CWE-73",
      "title": "Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85668"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-85671",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netease-youdao",
      "product": "QAnything",
      "cwe": "CWE-306",
      "title": "QAnything 2.0.0 Unauthenticated Cross-User File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85671"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-85673",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hiyouga",
      "product": "LlamaFactory",
      "cwe": "CWE-918",
      "title": "LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85673"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-85675",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "camel-ai",
      "product": "owl",
      "cwe": "CWE-918",
      "title": "OWL DocumentProcessingToolkit Server-Side Request Forgery via URL Fetching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85675"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-85685",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agentscope-ai",
      "product": "agentscope",
      "cwe": "CWE-22",
      "title": "AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85685"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-85686",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelscope",
      "product": "ms-swift",
      "cwe": "CWE-918",
      "title": "ms-swift 4.5.2 Unauthenticated SSRF via Multimodal Media URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85686"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-85687",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datalab-to",
      "product": "surya",
      "cwe": "CWE-73",
      "title": "surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85687"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-85691",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The-Vibe-Company",
      "product": "megaparse",
      "cwe": "CWE-918",
      "title": "MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85691"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-85699",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jina-ai",
      "product": "reader",
      "cwe": "CWE-918",
      "title": "jina-ai reader server-side request forgery via redirect validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85699"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-85786",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "ion-java",
      "cwe": "CWE-409",
      "title": "Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85786"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-19305",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19305"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-50553",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "enchant97",
      "product": "note-mark",
      "cwe": "CWE-20",
      "title": "Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50553"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-82684",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tycon Systems",
      "product": "TPDIN-Monitor-WEB3",
      "cwe": "CWE-862",
      "title": "Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82684"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-82712",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tycon Systems",
      "product": "TPDIN-Monitor-WEB3",
      "cwe": "CWE-352",
      "title": "Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82712"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-4644",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Integration Connectors",
      "cwe": "CWE-863",
      "title": "Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4644"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-6958",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Invicti Security Corp.",
      "product": "Acunetix",
      "cwe": "CWE-427",
      "title": "Acunetix 25.11.251107123 Local Privilege Escalation via wvsc.exe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6958"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-80112",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-732",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80112"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-80114",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-321",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authentication Bypass via DirectIo64.sys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80114"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-80116",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-782",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80116"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-80119",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-73",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80119"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-85656",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "log4j-cve-2021-44228-hotpatch",
      "cwe": "CWE-78",
      "title": "OS command injection in Amazon log4j-cve-2021-44228-hotpatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85656"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-85674",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aider-AI",
      "product": "aider",
      "cwe": "CWE-94",
      "title": "aider 0.86.2 Remote Code Execution via .aider.conf.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85674"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-85690",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plandex-ai",
      "product": "plandex",
      "cwe": "CWE-22",
      "title": "Plandex 2.2.1 Path Traversal via ApplyFiles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85690"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-86095",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unidata",
      "product": "netcdf-c",
      "cwe": "CWE-787",
      "title": "Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86095"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-57159",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-129",
      "title": "PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57159"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-80118",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-73",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80118"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-85613",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-79",
      "title": "OpenPanel Unauthenticated XSS via SVG Favicon Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85613"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-85616",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-639",
      "title": "Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85616"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-85651",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-862",
      "title": "Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85651"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-52769",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-918",
      "title": "YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52769"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-52771",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52771"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-57164",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-122",
      "title": "PJSIP: Heap overflow in the HTTP client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57164"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-86098",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntop",
      "product": "nDPI",
      "cwe": "CWE-787",
      "title": "ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86098"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-52767",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-347",
      "title": "YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52767"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-53761",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "crm",
      "cwe": "CWE-287",
      "title": "Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53761"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-77822",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "ContextForge MCP Gateway",
      "cwe": "CWE-918",
      "title": "IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77822"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-82728",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-770",
      "title": "Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82728"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-85596",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-287",
      "title": "Traefik v3.7 Authentication Bypass via TLS Option Conflict",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85596"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-85597",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-863",
      "title": "Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85597"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-85730",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "squirrelchat",
      "product": "smol-toml",
      "cwe": "CWE-606",
      "title": "smol-toml: Denial of Service via malformed TOML documents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85730"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-18175",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-285",
      "title": "IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18175"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-18221",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-287",
      "title": "IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18221"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-19303",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19303"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-61699",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgekeep",
      "product": "nebula-mesh",
      "cwe": "CWE-299",
      "title": "nebula-mesh: Certificate revocation is never enforced at the mesh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61699"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-53932",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stefanzweifel",
      "product": "laravel-backup-restore",
      "cwe": "CWE-77",
      "title": "wnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53932"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-85649",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chewkeanho",
      "product": "software-actualizer",
      "cwe": "CWE-252",
      "title": "(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and unconditionally accepts the result. If mkpasswd fails to generate a yescrypt hash, for example because an incompatible mkpasswd implementation or an environment without yescrypt support is used, the resulting password hash variable can be empty and the build proceeds. The resulting image can therefore contain empty password fields for the root and alpha accounts, potentially permitting passwordless authentication depending on the authentication configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85649"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-18905",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "ContextForge MCP Gateway (`mcp-contextforge-gateway`)",
      "cwe": "CWE-918",
      "title": "IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18905"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-19283",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Observability with Instana (Agent)",
      "cwe": "CWE-863",
      "title": "IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19283"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-19304",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19304"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-19306",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19306"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-63464",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgekeep",
      "product": "nebula-mesh",
      "cwe": "CWE-862",
      "title": "Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63464"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-81832",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-611",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81832"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-85619",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AppFlowy-IO",
      "product": "AppFlowy-Cloud",
      "cwe": "CWE-863",
      "title": "AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85619"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2021-44320",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-44320"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-12483",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StellarWP",
      "product": "LearnDash LMS",
      "cwe": "CWE-434",
      "title": "LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12483"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-19080",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Menulux Software Inc.",
      "product": "Menulux Portal",
      "cwe": "CWE-204",
      "title": "Username Enumeration in Menulux Software's Menulux Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19080"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-19205",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GastroMenum",
      "product": "GastroMenum Web Panel",
      "cwe": "CWE-204",
      "title": "User Enumeration in GastroMenum's GastroMenum Web Panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19205"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-19300",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-200",
      "title": "Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19300"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-19534",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-248",
      "title": "undici vulnerable to Denial of Service via unrequested WebSocket subprotocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19534"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-52770",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52770"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-61686",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolidInvoice",
      "product": "SolidInvoice",
      "cwe": "CWE-502",
      "title": "SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61686"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-84428",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify",
      "product": "fastify",
      "cwe": "CWE-178",
      "title": "fastify vulnerable to header validation bypass via incomplete schema case normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84428"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-18489",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "ContextForge MCP Gateway - Translate utility",
      "cwe": "CWE-488",
      "title": "IBM ContextForge Translate is affected by cross-client credential context confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18489"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-84961",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-295",
      "title": "undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84961"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-85152",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-346",
      "title": "undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85152"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2022-35499",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-35499"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-19051",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Menulux Software Inc.",
      "product": "Menulux Portal",
      "cwe": "CWE-256",
      "title": "Plaintext Storage of User Credentials in Menulux Software's Menulux Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19051"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-52762",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-1336",
      "title": "YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52762"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-53603",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgekeep",
      "product": "nebula-mesh",
      "cwe": "CWE-312",
      "title": "nebula-mesh: Operator session tokens stored in plaintext in the database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53603"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-53604",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgekeep",
      "product": "nebula-mesh",
      "cwe": "CWE-212",
      "title": "nebula-mesh: CA private key not zeroized on web mobile-bundle error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53604"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-74237",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Exinda AI",
      "cwe": "CWE-88",
      "title": "GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74237"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-77847",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tycon Systems",
      "product": "TPDIN-Monitor-WEB3",
      "cwe": "CWE-798",
      "title": "Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77847"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-85578",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan through 3.8.1 Authorization Bypass via getFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85578"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-85580",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85580"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-85582",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-770",
      "title": "SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85582"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-85583",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-59",
      "title": "SiYuan before v3.8.2 Path Traversal via symlink in file API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85583"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-85590",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-308",
      "title": "phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85590"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-85591",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-620",
      "title": "phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85591"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-85603",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-73",
      "title": "Grav Admin Plugin Path Traversal via Save As Language Code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85603"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-85618",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "C4illin",
      "product": "ConvertX",
      "cwe": "CWE-22",
      "title": "ConvertX 0.17.0 Arbitrary File Read via LaTeX Input Directives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85618"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-85624",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blinkospace",
      "product": "blinko",
      "cwe": "CWE-639",
      "title": "Blinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceList",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85624"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-85654",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "awslabs.dynamodb-mcp-server",
      "cwe": "CWE-1336",
      "title": "Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85654"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-85665",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usebruno",
      "product": "bruno",
      "cwe": "CWE-22",
      "title": "Bruno 3.4.2 Arbitrary File Read via Unconfined Body File Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85665"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-85669",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "potpie-ai",
      "product": "potpie",
      "cwe": "CWE-862",
      "title": "potpie through 2.0.0 Missing Ownership Check via code-changes sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85669"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-85670",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "tokenizers",
      "cwe": "CWE-787",
      "title": "tokenizers BpeBuilder Buffer Overflow via merge token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85670"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-85689",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "llmware-ai",
      "product": "llmware",
      "cwe": "CWE-89",
      "title": "llmware 0.4.6 SQL Injection via unescaped filter values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85689"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-85692",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ccfos",
      "product": "nightingale",
      "cwe": "CWE-918",
      "title": "Nightingale 9.1.1 SSRF Guard Bypass via IPv6 Encoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85692"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-85693",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mckaywrigley",
      "product": "chatbot-ui",
      "cwe": "CWE-639",
      "title": "Chatbot UI Cross-User Private File Content Disclosure via Retrieval API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85693"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-85697",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "documenso",
      "product": "documenso",
      "cwe": "CWE-863",
      "title": "Documenso 2.17.0 PDF Route Ignores Document Visibility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85697"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-85700",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onyx-dot-app",
      "product": "onyx",
      "cwe": "CWE-522",
      "title": "Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85700"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-85787",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "postgres-mcp-server",
      "cwe": "CWE-184",
      "title": "An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85787"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-86090",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntop",
      "product": "ntopng",
      "cwe": "CWE-862",
      "title": "ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86090"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-86091",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntop",
      "product": "ntopng",
      "cwe": "CWE-862",
      "title": "ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86091"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-86097",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PX4",
      "product": "PX4-Autopilot",
      "cwe": "CWE-476",
      "title": "PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86097"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-74236",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Exinda AI",
      "cwe": "CWE-22",
      "title": "GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74236"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-85594",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-639",
      "title": "Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85594"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-53602",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgekeep",
      "product": "nebula-mesh",
      "cwe": "CWE-285",
      "title": "nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid certificate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53602"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-53757",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-22",
      "title": "Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53757"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-57160",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-193",
      "title": "PJSIP: SIP message header buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57160"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-73848",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-79",
      "title": "Emlog: Stored XSS via Tag Name in Article Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73848"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-74235",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Exinda AI",
      "cwe": "CWE-22",
      "title": "GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74235"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-80113",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-782",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.sys IOCTL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80113"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-80115",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-782",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR Write IOCTL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80115"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-80117",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PassMark Software",
      "product": "PerformanceTest",
      "cwe": "CWE-782",
      "title": "PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via DirectIo64.sys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80117"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-85586",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-799",
      "title": "phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85586"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-85605",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andrii-kryvoviaz",
      "product": "slink",
      "cwe": "CWE-862",
      "title": "Slink before 1.12.3 Missing Authorization on Image Comment Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85605"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-85609",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-918",
      "title": "Openpanel before 2.3.0 SSRF via Site Checker Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85609"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-85621",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobehub",
      "cwe": "CWE-345",
      "title": "LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85621"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-85662",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marqo-ai",
      "product": "marqo",
      "cwe": "CWE-918",
      "title": "Marqo 2.26.0 Server-Side Request Forgery via Media URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85662"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-61608",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolidInvoice",
      "product": "SolidInvoice",
      "cwe": "CWE-613",
      "title": "SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61608"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-85698",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tursodatabase",
      "product": "turso",
      "cwe": "CWE-125",
      "title": "Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85698"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-5522",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "QRadar",
      "cwe": "CWE-798",
      "title": "QRadar contains hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5522"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-9138",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9138"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-9186",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-284",
      "title": "Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9186"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-14470",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14470"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-17057",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-306",
      "title": "IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17057"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-17207",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17207"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-17273",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-476",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17273"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-17622",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17622"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-18887",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-200",
      "title": "IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18887"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-19299",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19299"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-19302",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19302"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-19645",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ Agent",
      "cwe": "CWE-400",
      "title": "Multiple vulnerabilities in IBM MQ Agent images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19645"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-52763",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-89",
      "title": "YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52763"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-53769",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "avo-hq",
      "product": "avo",
      "cwe": "CWE-862",
      "title": "Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53769"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-61688",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolidInvoice",
      "product": "SolidInvoice",
      "cwe": "CWE-639",
      "title": "SolidInvoice allows cross-user access to API token request history via writable DataGrid LiveComponent props",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61688"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-75163",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75163"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-75164",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-552",
      "title": "An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75164"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-78658",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "UCD - IBM UrbanCode Deploy",
      "cwe": "CWE-212",
      "title": "IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78658"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-78970",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-862",
      "title": "JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve sensitive information of all users, including real names, phone numbers, email addresses, employee numbers, and role definitions, due to missing fine-grained permission checks and incomplete data desensitization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78970"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-84933",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-200",
      "title": "undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84933"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-85769",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85769"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-18341",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-122",
      "title": "IBM i is Affected By Buffer Overflow Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18341"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-57165",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-121",
      "title": "PJSIP: Pre-authentication overflow in the telnet CLI history",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57165"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-57166",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-121",
      "title": "PJSIP: Pre-authentication overflow in the telnet CLI error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57166"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-75168",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75168"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-82729",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-407",
      "title": "Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82729"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-85592",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-863",
      "title": "phpMyFAQ before 4.1.8 Authorization Bypass via question/create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85592"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-16689",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-532",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16689"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-19649",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-532",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19649"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-81859",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Business Automation",
      "cwe": "CWE-327",
      "title": "Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81859"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-8447",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-79",
      "title": "Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8447"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-19727",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.",
      "product": "Library Information and Document Automation Program",
      "cwe": "CWE-79",
      "title": "HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19727"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-52773",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-80",
      "title": "Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52773"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-52774",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-80",
      "title": "Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52774"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-77818",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.",
      "product": "Library Information and Document Automation Program",
      "cwe": "CWE-79",
      "title": "Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77818"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-85622",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AppFlowy-IO",
      "product": "AppFlowy-Cloud",
      "cwe": "CWE-863",
      "title": "AppFlowy-Cloud through 0.9.64 Cross-Workspace Collab Read via WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85622"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-86096",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PX4",
      "product": "PX4-Autopilot",
      "cwe": "CWE-416",
      "title": "PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86096"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-18149",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-772",
      "title": "undici vulnerable to Denial of Service via orphaned RetryHandler response body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18149"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-61614",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolidInvoice",
      "product": "SolidInvoice",
      "cwe": "CWE-598",
      "title": "SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61614"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-84890",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-770",
      "title": "undici vulnerable to Denial of Service via unbounded decompression of compressed responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84890"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-85014",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-248",
      "title": "undici vulnerable to Denial of Service via WebSocketStream unclean close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85014"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-85024",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-248",
      "title": "undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85024"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-85534",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-617",
      "title": "Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85534"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-76925",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-367",
      "title": "Flatpak: flatpak: toctou race condition allows symlink redirection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76925"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-16180",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-776",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16180"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-17440",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-674",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17440"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-52772",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-79",
      "title": "YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52772"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-85512",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-862",
      "title": "SourceCodester Class and Exam Timetabling System session.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85512"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-85516",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Vehicle Management System",
      "cwe": "CWE-74",
      "title": "code-projects Vehicle Management System busprofile.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85516"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-85517",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Vehicle Management System",
      "cwe": "CWE-200",
      "title": "code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85517"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-85522",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valkey-io",
      "product": "valkey",
      "cwe": "CWE-119",
      "title": "valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85522"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-85636",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jofpin",
      "product": "trape",
      "cwe": "CWE-287",
      "title": "jofpin trape Login Endpoint stats.py missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85636"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-85637",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jofpin",
      "product": "trape",
      "cwe": "CWE-287",
      "title": "jofpin trape Admin Endpoint sockets.py join_room missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85637"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-85638",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jofpin",
      "product": "trape",
      "cwe": "CWE-285",
      "title": "jofpin trape user.py authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85638"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-85701",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ramon-victor",
      "product": "freegpt-webui",
      "cwe": "CWE-287",
      "title": "ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85701"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-85702",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ramon-victor",
      "product": "freegpt-webui",
      "cwe": "CWE-287",
      "title": "ramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85702"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-85703",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ramon-victor",
      "product": "freegpt-webui",
      "cwe": "CWE-400",
      "title": "ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85703"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-16892",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-287",
      "title": "IBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16892"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-17274",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-330",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17274"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-17621",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17621"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-18957",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Menulux Software Inc.",
      "product": "Menulux Portal",
      "cwe": "CWE-79",
      "title": "Stored XSS in Menulux Software's Menulux Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18957"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-19057",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gastromenum",
      "product": "Gastromenum Ticket and QR Menu System",
      "cwe": "CWE-79",
      "title": "Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19057"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-55513",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgekeep",
      "product": "nebula-mesh",
      "cwe": "CWE-613",
      "title": "nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55513"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-14350",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Data System",
      "cwe": "CWE-117",
      "title": "Vulnerabilities exists in IBM Cloud Pak for Data System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14350"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-16660",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-125",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16660"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-16826",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16826"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-17443",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-611",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17443"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-17444",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-611",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17444"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-17469",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17469"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-17470",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17470"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-27347",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetPopup",
      "cwe": "CWE-862",
      "title": "WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27347"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-55512",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgekeep",
      "product": "nebula-mesh",
      "cwe": "CWE-400",
      "title": "nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55512"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-78543",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-835",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78543"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-84045",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "E-cab Taxi Booking Manager for Woocommerce",
      "cwe": null,
      "title": "E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation via mptbm_add_to_cart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84045"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-85577",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo userLogin.php Reflected XSS via error parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85577"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-85579",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-639",
      "title": "SiYuan before v3.8.2 Information Disclosure via undoState",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85579"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-85587",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-863",
      "title": "phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85587"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-85588",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-200",
      "title": "phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85588"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-85589",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-862",
      "title": "phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85589"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-85611",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-639",
      "title": "OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85611"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-85615",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-639",
      "title": "Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85615"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-85650",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-918",
      "title": "Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85650"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-85676",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dubinc",
      "product": "dub",
      "cwe": "CWE-601",
      "title": "Dub Open Redirect via Unrestricted redir_url Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85676"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-86100",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "CamaleonCMS",
      "cwe": "CWE-918",
      "title": "Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86100"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-53760",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-352",
      "title": "Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53760"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-17442",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-532",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17442"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-82911",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-352",
      "title": "CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82911"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-85593",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-79",
      "title": "phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85593"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-85598",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85598"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-85599",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85599"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-85600",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav Admin before 2.0.21 Stored XSS via username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85600"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-85601",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav Admin before 2.0.20 Cross-Site Scripting via marked.js",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85601"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-85781",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aws",
      "product": "aws-efs-csi-driver",
      "cwe": "CWE-283",
      "title": "Unverified access point ownership in Amazon EFS CSI Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85781"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-17631",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17631"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-19301",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19301"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-17627",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17627"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-53756",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-89",
      "title": "Emlog Blind SQL Injection via Authentication Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53756"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-16693",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-327",
      "title": "IBM i is Affected By Cryptographic Algorithm Weakness in DCM []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16693"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-17499",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17499"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-18073",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18073"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-18567",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-367",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18567"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-14466",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stormshield",
      "product": "Stormshield Network Security",
      "cwe": "CWE-79",
      "title": "Possible XSS in the SNS web administration panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14466"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-16941",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-863",
      "title": "IBM i is Affected By An Incorrect Authorization Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16941"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-17255",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Denial of Service Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17255"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-17259",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-121",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17259"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-17270",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-121",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17270"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-17483",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-285",
      "title": "IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17483"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-18076",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-401",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Debug Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18076"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-18078",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-190",
      "title": "IBM i is Affected By Denial of Service Vulnerability in Save Restore []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18078"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-19043",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Menulux Software Inc.",
      "product": "Menulux Portal",
      "cwe": "CWE-862",
      "title": "Authorization Bypass Critical POS Management Functions in Menulux Software's Menulux Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19043"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-19081",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gastromenum",
      "product": "Gastromenum Ticket and QR Menu System",
      "cwe": "CWE-862",
      "title": "Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum's Gastromenum Ticket and QR Menu System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19081"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-18540",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-444",
      "title": "undici vulnerable to downstream response splitting via retry interceptor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18540"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-84947",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-20",
      "title": "undici vulnerable to response truncation via oversized chunked responses in the dump interceptor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84947"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-85008",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-345",
      "title": "undici vulnerable to caching and replay of unsafe HTTP method responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85008"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-18858",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-267",
      "title": "IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18858"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-85639",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jofpin",
      "product": "trape",
      "cwe": "CWE-362",
      "title": "jofpin trape Telemetry Endpoint user.py race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85639"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-85704",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ramon-victor",
      "product": "freegpt-webui",
      "cwe": "CWE-362",
      "title": "ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85704"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-85513",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StackStorm",
      "product": "st2",
      "cwe": "CWE-266",
      "title": "StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85513"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-85514",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StackStorm",
      "product": "st2",
      "cwe": "CWE-266",
      "title": "StackStorm st2 API Key auth.py privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85514"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-85643",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Shopping System",
      "cwe": "CWE-74",
      "title": "code-projects Online Shopping System adduser.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85643"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2021-44319",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-44319"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2022-26961",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-26961"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2022-35497",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-35497"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2025-67066",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67066"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-13297",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-1336",
      "title": "Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13297"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-38961",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38961"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-50894",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50894"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-52691",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Griffin Hive Metastore Module",
      "cwe": "CWE-89",
      "title": "Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52691"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-71620",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71620"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-71622",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71622"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-71624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71624"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-71625",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71625"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-71626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71626"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-75161",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75161"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-75162",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75162"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-75165",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75165"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-75166",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75166"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-75167",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75167"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-75169",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75169"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-75170",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75170"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-75171",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75171"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-75429",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75429"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-75438",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75438"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-75439",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75439"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-78745",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78745"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-78839",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78839"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-78849",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78849"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-79389",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce, timestamp, and signature fields, and the device accepts the modified messages and executes the associated commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79389"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-79390",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can intercept MQTT traffic and obtain sensitive device information and operational data, including device identifiers, message metadata, and control-related information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79390"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-79391",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79391"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-79418",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79418"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-79419",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79419"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-79423",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79423"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-79426",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79426"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-80758",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex: Avoid private hash use-after-free on final put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80758"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-80759",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_aml: validate firmware segment lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80759"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-80760",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80760"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-80761",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: ISO: zero the sockaddr before returning it in getname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80761"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-80762",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sync: Fix accept list UAF during suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80762"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-80763",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_event: validate LE Set CIG Parameters response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80763"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-80764",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_event: fix LE list UAF on reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80764"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-80765",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: hyperv: validate initial device info bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80765"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-80766",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: uclogic: fix use-after-free of inrange_timer on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80766"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-80767",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: sensor: custom: Fix use-after-free in enable_sensor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80767"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-80768",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: ft260: fix stack-use-after-return write in I2C read race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80768"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-80769",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: rapoo: fix missing hid_is_usb() check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80769"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-80770",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: nintendo: stop device IO before hid_hw_stop on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80770"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-80771",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: nintendo: register input device after capabilities are set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80771"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-80772",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80772"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-80773",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: huawei: fix missing hid_is_usb() check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80773"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-80774",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: asus: fix missing hid_is_usb() check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80774"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-80775",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex: Fix race on the initial mm->futex.phash.ref allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80775"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-80776",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex: Fix race in futex_pivot_pending() during private hash resize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80776"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-80777",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex/pi: Plug private futex exec() race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80777"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-80778",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex/pi: Reject cross-mm private futex owners",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80778"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-80779",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/ionic: avoid OOB TX partner lookup for hwstamp RXQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80779"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-80780",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: pidff: fix OOB write when hid->inputs is empty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80780"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-80781",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: core: fix OOB read of field->usage in hid_set_field()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80781"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-80782",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: magicmouse: do not keep a stale msc->input if no input is claimed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80782"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-80783",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80783"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-80784",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: pm: fix memory leak from alloc-during-teardown race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80784"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-80785",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: serialize mode sysfs access with lock_fb_info()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80785"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-80786",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: Wrap user-invoked calls to fb_set_var() in helper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80786"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-80787",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80787"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-80788",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80788"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-80789",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-tcp: bound SGL data length before allocating command buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80789"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-80790",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-fc: fix invalid free in LS IOD error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80790"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-80791",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-auth: zero the AUTH_RECEIVE response buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80791"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-80792",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: fix use-after-free in ip6_finish_output2()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80792"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-80793",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: reject undersized MTUs in ip_do_fragment()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80793"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-80794",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: nci: fix uninit-value in the RF discover/activated NTF handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80794"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-80795",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: nci: fix out-of-bounds write in nci_target_auto_activated()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80795"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-80796",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: nci: add data_len bound checks to activation parameter extractors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80796"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-80797",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: pn533: purge fragmented skbs during cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80797"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-80798",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: llcp: reject PDUs shorter than the LLCP header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80798"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-80799",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80799"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-80800",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: llcp: bound the connect_sn TLV walk to the skb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80800"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-80801",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: microread: validate target discovery payload lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80801"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-80802",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: fdp: bound the device-reported read length and fix an skb leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80802"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-80803",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: digital: clamp SENSF_RES length to the destination buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80803"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-80804",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: restore nofs context unconditionally in xfs_trans_roll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80804"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-80805",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: validate attr entry pointer before field access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80805"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-80806",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: don't enable DAX on new encrypted files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80806"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-80807",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nilfs2: reject invalid block index in GC ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80807"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-80808",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: stop retrying saturated xattr cache entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80808"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-80809",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: fix missing metadata reservation for large xattrs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80809"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-80810",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80810"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-80811",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/cmd: fix iovec leak when the async cmd is not recycled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80811"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-80812",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: dummy: Check card index validity at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80812"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-80813",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80813"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-80814",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rndis_host: add overflow check in rndis_rx_fixup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80814"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-80815",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: scarlett2: Use a private URB for the notification endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80815"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-80816",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: FCP: Use a private URB for the notification endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80816"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-80817",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80817"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-80818",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80818"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-80819",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80819"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-80820",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfs: don't livelock in scrub on a circular unlinked list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80820"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-80821",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: pci-epf: put CQ ref on create_cq mapping failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80821"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-80822",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80822"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-80823",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: st21nfca: validate ATR_REQ length against the received frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80823"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-80824",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: usbfs: fix use-after-free of usb_device in usbdev_release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80824"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-80825",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80825"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-80826",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: c67x00: fix use-after-free in c67x00_add_iso_urb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80826"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-80827",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: serial: option: fix slab OOB read in interrupt URB callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80827"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-80828",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: Complete cleanup after system-resume errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80828"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-80829",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80829"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-80830",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: core: Add lock to usb_wakeup_notification()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80830"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-80831",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: mxs-dcp - fix source scatterlist length access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80831"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-80832",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qce - fix CCM AAD buffer underallocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80832"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-80833",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: sun8i-ss - Remove crypto_rng interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80833"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-80834",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: sun8i-ce - Remove crypto_rng interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80834"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-80835",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qcom-rng - Remove crypto_rng interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80835"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-80836",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: virtio - bound the akcipher result length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80836"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-80837",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_tables: don't queue packet path object notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80837"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-80838",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: keep the last remote linked during FDB flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80838"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-80839",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: reject unrepresentable multicast TVLV offsets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80839"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-80840",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: seg6: clear IPv4 control block on IPIP decapsulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80840"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-80841",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/packet: defer vmalloc TX_RING free until skbs finish",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80841"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-80842",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: mcast: fix use-after-free of a master VLAN's multicast context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80842"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-80843",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: fix xfrm_state_construct() auth-trunc leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80843"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-80844",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: ah6: validate routing header segments_left",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80844"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-80845",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: avoid lock inversion in nat keepalive work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80845"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-80846",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: drop ESP-in-TCP packets with no ingress device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80846"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-80847",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: clamp route advmss to TCP_MIN_MSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80847"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-80848",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: espintcp: fix UAF during close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80848"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-80849",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/tcp-ao: fix use-after-free of current_key on reconnect to another peer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80849"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-80850",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: fix AO info use-after-free in tcp_ao_connect_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80850"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-80851",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gtp: serialize PDP context updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80851"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-80852",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tls: device: fix out-of-bounds write in tls_append_frag()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80852"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-80853",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80853"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-80854",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_tcm: keep port count until LUN teardown completes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80854"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-80855",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: fix invalidate lock leak on open O_TRUNC DAX failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80855"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-80856",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: fix invalidate lock leak on setattr writeback failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80856"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-80857",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80857"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-80858",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: publish io-uring queues with release semantics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80858"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-80859",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: fix missing barrier when checking io-uring readiness",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80859"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-80860",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: fix race between interrupt and resend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80860"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-80861",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: xhci: bail out of setup if the controller is inaccessible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80861"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-80862",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-tcp: fix usage of page_frag_cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80862"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-80863",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Fix OOB in free_rd_atomic_resources()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80863"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-80864",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80864"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-80865",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Add missing access_ok call to copy_user_syms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80865"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-80866",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: avoid busy looping in tipc_exit_net()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80866"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-80867",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "alpha/PCI: Add security_locked_down() check to pci_mmap_resource()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80867"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-80868",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs3: Allocate iomap inline_data using alloc_page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80868"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-80869",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: bound the attribute-list entry in ntfs_read_inode_mount()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80869"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-80870",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Validate CRIU-restored IDs before idr_alloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80870"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-80871",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: xilinx-trng - Remove crypto_rng interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80871"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-80872",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: hda/tas2781: Cancel async firmware request at unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80872"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-80873",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80873"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-80874",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: dts: renesas: ironhide: Describe inline ECC carveouts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80874"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-80875",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: use parsed transport offset in TCP state lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80875"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-80876",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ring-buffer: Fix event length with forced 8-byte alignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80876"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-80877",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Fix vllist leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80877"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-80878",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Fix leak of ungot volume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80878"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-80879",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80879"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-80880",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/mlx5: Properly support implicit ODP rereg_mr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80880"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-80881",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: fix buffer head management in ocfs2_read_blocks()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80881"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-80882",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80882"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-80883",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80883"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-80884",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntb: Store original DMA address for future release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80884"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-80885",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "afs: Fix uncancelled rxrpc OOB message handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80885"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-80886",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: msm: Disable DMA for kernel console UART",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80886"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-80887",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vmwgfx: use check_add_overflow for shader size+offset bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80887"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-80888",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vmwgfx: drop dma_buf reference on foreign-fd prime import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80888"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-80889",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "can: isotp: fix timer drain order, wakeup handling and tx_gen ordering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80889"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-80890",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: reject stale cookies with mismatched verification tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80890"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-80891",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: pci: Validate AIBV and AISB before pinning guest pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80891"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-80892",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: cap LZMA stream pool size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80892"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-80893",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80893"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-80894",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80894"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-80895",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mshv: Order pt_vp_array publish against irqfd assertion path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80895"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-80896",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mshv: Fix race in mshv_irqfd_deassign",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80896"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-80897",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfs: release readahead folios on iterator preparation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80897"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-80898",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfs: clear PG_private_2 on copy-to-cache append failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80898"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-80899",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: remove fscache backend entirely",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80899"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-80900",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: SDCA: Make UMP message size check more robust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80900"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-80901",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: fix the checksum validations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80901"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-80902",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80902"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-80903",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe/oa: Fix sync entry leak on OA config emit failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80903"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-80904",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/tls: Fail tls_sw_splice_read() after a failed async decrypt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80904"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-80905",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: tap: fix wrong transport_header when sending VLAN-tagged frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80905"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-80906",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: packet: fix wrong transport_header when sending VLAN-tagged frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80906"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-80907",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Fix UVD dpb min size calculation for H264",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80907"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-80908",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Reject UVD message with dimensions above 4096",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80908"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-80909",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Reject UVD message with invalid number of h265 refs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80909"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-80910",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80910"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-80911",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80911"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-80912",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: reject an unclaimed class value in security_get_classes()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80912"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-80913",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: require every boolean value to be defined",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80913"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-82309",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Robots-Validate",
      "cwe": "CWE-405",
      "title": "Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82309"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-85046",
      "detail": "ADDED TO KEV — CVE-2026-85046 (Google Chrome). Remediation due September 18, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62718",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62718 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25639 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32141",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33228",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33228 (WebReflection flatted). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33891",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33891 (digitalbazaar forge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33896 (digitalbazaar forge). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33937",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33937 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33938",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33938 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33939 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33940",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33940 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33941",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33941 (handlebars-lang handlebars.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35172",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35172 (distribution). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39956",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39956 (jqlang jq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40175",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40175 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41035",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42033 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42039 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42043",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42043 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43820",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43820 (Apple swift-nio-ssl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43997 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43998 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43999",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43999 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44005",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44005 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44007 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44009",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44009 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45411 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52022",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52022. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56718",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56718 (AJCloud AJY IPC Firmware). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67620 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71962",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71962 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73602",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73602 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73603",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73603 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73604",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73604 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82524",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82526 (SciPhi-AI R2R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82527",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82527 (SciPhi-AI R2R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84841",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84841 (tsi-coop tsi-dpdp-cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84886",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84886 (simular-ai Agent-S). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85030",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85030 (HKUDS AI-Trader). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85137",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85137 (SeaCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85186",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85186 (itsourcecode Online Medicine Delivery System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85187",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85187 (itsourcecode Online Medicine Delivery System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85207",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85207 (itsourcecode Online Medicine Delivery System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85208",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85208 (itsourcecode Online Medicine Delivery System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85222",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85222 (D-Link DNS-340L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85223",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85223 (D-Link DNS-340L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85224",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85224 (D-Link DNS-320 ShareCenter). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85225 (code-projects Doctor Appointment System). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-72530",
      "detail": "DUE DATE PASSED — CVE-2026-72530 (TrueConf Server). CISA remediation deadline was September 3, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-67038",
      "detail": "RESCORED — CVE-2025-67038 (Lantronix EDS5000 series). CVSS 9.8 → 9.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12261",
      "detail": "RESCORED — CVE-2026-12261 (nltk/nltk). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-13732",
      "detail": "RESCORED — CVE-2026-13732 (Red Hat Enterprise Linux 10). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18165",
      "detail": "RESCORED — CVE-2026-18165 (@fastify/oauth2). CVSS 4.2 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18824",
      "detail": "RESCORED — CVE-2026-18824 (IBM AIX). CVSS 8.4 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47834",
      "detail": "RESCORED — CVE-2026-47834 (Spring Data JPA). CVSS 4.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47836",
      "detail": "RESCORED — CVE-2026-47836 (Spring Cloud Config). CVSS 7.2 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47837",
      "detail": "RESCORED — CVE-2026-47837 (Spring Cloud Config). CVSS 6.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47844",
      "detail": "RESCORED — CVE-2026-47844 (Spring Reactor Netty). CVSS 5.3 → 3.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47859",
      "detail": "RESCORED — CVE-2026-47859 (Spring Integration). CVSS 5.4 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59301",
      "detail": "RESCORED — CVE-2026-59301 (Spring Cloud Function). CVSS 3.1 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59303",
      "detail": "RESCORED — CVE-2026-59303 (Spring Cloud Stream). CVSS 3.1 → 3.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59304",
      "detail": "RESCORED — CVE-2026-59304 (Spring Cloud Stream). CVSS 3.1 → 3.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59305",
      "detail": "RESCORED — CVE-2026-59305 (Spring Cloud Stream). CVSS 3.1 → 3.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59306",
      "detail": "RESCORED — CVE-2026-59306 (Spring Cloud Stream). CVSS 3.1 → 3.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63509",
      "detail": "RESCORED — CVE-2026-63509 (Microsoft Fabric). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69419",
      "detail": "RESCORED — CVE-2026-69419 (Microsoft Azure Data Manager for Energy). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70105",
      "detail": "RESCORED — CVE-2026-70105 (Microsoft 365 Apps for Enterprise). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72670",
      "detail": "RESCORED — CVE-2026-72670 (Elastic Kibana). CVSS 7.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72676",
      "detail": "RESCORED — CVE-2026-72676 (Elastic Fleet Server). CVSS 6.5 → 9.1 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-61485",
      "detail": "REJECTED — CVE-2026-61485 (Apache Software Foundation Apache Lucy). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2025-67038",
      "detail": "PATCH SHIPPED — CVE-2025-67038 (Lantronix EDS5000 series). Fixed in EDS5000 series 2.2.0.0R1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-55985",
      "detail": "PATCH SHIPPED — CVE-2026-55985 (Tycon Systems TPDIN-Monitor-WEB2). Fixed in TPDIN-Monitor-WEB2 2.4.5."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-61884",
      "detail": "PATCH SHIPPED — CVE-2026-61884 (Tycon Systems TPDIN-Monitor-WEB2). Fixed in TPDIN-Monitor-WEB2 2.4.5."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64307",
      "detail": "ENRICHED — CVE-2026-64307 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64308",
      "detail": "ENRICHED — CVE-2026-64308 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64309",
      "detail": "ENRICHED — CVE-2026-64309 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64310",
      "detail": "ENRICHED — CVE-2026-64310 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64321",
      "detail": "ENRICHED — CVE-2026-64321 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64325",
      "detail": "ENRICHED — CVE-2026-64325 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64326",
      "detail": "ENRICHED — CVE-2026-64326 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64327",
      "detail": "ENRICHED — CVE-2026-64327 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64328",
      "detail": "ENRICHED — CVE-2026-64328 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64329",
      "detail": "ENRICHED — CVE-2026-64329 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64330",
      "detail": "ENRICHED — CVE-2026-64330 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64356",
      "detail": "ENRICHED — CVE-2026-64356 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64357",
      "detail": "ENRICHED — CVE-2026-64357 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64358",
      "detail": "ENRICHED — CVE-2026-64358 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64359",
      "detail": "ENRICHED — CVE-2026-64359 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64360",
      "detail": "ENRICHED — CVE-2026-64360 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64362",
      "detail": "ENRICHED — CVE-2026-64362 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64363",
      "detail": "ENRICHED — CVE-2026-64363 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64365",
      "detail": "ENRICHED — CVE-2026-64365 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64404",
      "detail": "ENRICHED — CVE-2026-64404 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64405",
      "detail": "ENRICHED — CVE-2026-64405 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64407",
      "detail": "ENRICHED — CVE-2026-64407 (Linux). Received CVSS 7.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64409",
      "detail": "ENRICHED — CVE-2026-64409 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64415",
      "detail": "ENRICHED — CVE-2026-64415 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64416",
      "detail": "ENRICHED — CVE-2026-64416 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64417",
      "detail": "ENRICHED — CVE-2026-64417 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64419",
      "detail": "ENRICHED — CVE-2026-64419 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64421",
      "detail": "ENRICHED — CVE-2026-64421 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64424",
      "detail": "ENRICHED — CVE-2026-64424 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64425",
      "detail": "ENRICHED — CVE-2026-64425 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64426",
      "detail": "ENRICHED — CVE-2026-64426 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64427",
      "detail": "ENRICHED — CVE-2026-64427 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64428",
      "detail": "ENRICHED — CVE-2026-64428 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
