{
  "day": "2026-09-06",
  "boundary": "UTC calendar day",
  "published_count": 92,
  "by_severity": {
    "CRITICAL": 6,
    "HIGH": 19,
    "MEDIUM": 41,
    "LOW": 15
  },
  "kev_count": 0,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 11,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-86152",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01859,
      "epss_percentile": 0.77821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CP3",
      "cwe": "CWE-77",
      "title": "Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86152"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-86167",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0163,
      "epss_percentile": 0.74627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG10",
      "cwe": "CWE-77",
      "title": "Tenda HG10 Boa formgponConf os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86167"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-86165",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00642,
      "epss_percentile": 0.48486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG10",
      "cwe": "CWE-119",
      "title": "Tenda HG10 formURL buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86165"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-75816",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.005,
      "epss_percentile": 0.41025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-287",
      "title": "Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75816"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-86166",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.3948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG10",
      "cwe": "CWE-119",
      "title": "Tenda HG10 Boa Web Server formWanRedirect buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86166"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-86218",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.3432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "N-able",
      "product": "N-central",
      "cwe": "CWE-96",
      "title": "pre-authentication remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86218"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-86153",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.31952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CP3",
      "cwe": "CWE-266",
      "title": "Tenda CP3 Redirect.cpp SetRedirectEnable privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86153"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-18056",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hivepress",
      "product": "HivePress Authentication",
      "cwe": "CWE-287",
      "title": "HivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook Authenticator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18056"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-86168",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Content Management System",
      "cwe": "CWE-74",
      "title": "code-projects Content Management System login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86168"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-86180",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System In PHP",
      "cwe": "CWE-74",
      "title": "code-projects Task Management System In PHP Login index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86180"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-86183",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "diem-project",
      "product": "diem",
      "cwe": "CWE-285",
      "title": "diem-project diem dmWidget BasedmWidgetActions.class.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86183"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-86179",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Daily Expense Manager",
      "cwe": "CWE-200",
      "title": "code-projects Daily Expense Manager Database Backup exp_ak.sql information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86179"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-16310",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LearnDash",
      "product": "MemberDash",
      "cwe": "CWE-639",
      "title": "MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16310"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-86159",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Voting System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Voting System ajax.php save_user sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86159"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-86160",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Voting System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Voting System ajax.php delete_voting sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86160"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-86161",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Voting System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Voting System ajax.php delete_category sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86161"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-86162",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.17986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Voting System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Voting System ajax.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86162"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-86181",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00208,
      "epss_percentile": 0.10934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System",
      "cwe": "CWE-79",
      "title": "code-projects Task Management System User Profile Update UpdateUserProfile.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86181"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-86164",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System trans_view.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86164"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-86163",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System pro_del.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86163"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-86172",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DefaultFuction",
      "product": "CRM",
      "cwe": "CWE-74",
      "title": "DefaultFuction CRM delete.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86172"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-86170",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.08961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DefaultFuction",
      "product": "CRM",
      "cwe": "CWE-74",
      "title": "DefaultFuction CRM edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86170"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-86171",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.08966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DefaultFuction",
      "product": "CRM",
      "cwe": "CWE-74",
      "title": "DefaultFuction CRM delete.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86171"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-84219",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-79",
      "title": "Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84219"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-86182",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "diem-project",
      "product": "diem",
      "cwe": "CWE-352",
      "title": "diem-project diem dmConsole actions.class.php executeCommand cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86182"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-84028",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84028"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-75793",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SureCart",
      "cwe": "CWE-284",
      "title": "SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75793"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-85038",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More",
      "cwe": "CWE-862",
      "title": "B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85038"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-18480",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SureCart",
      "cwe": "CWE-269",
      "title": "SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18480"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-13159",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Real Estate Papi",
      "cwe": "CWE-862",
      "title": "Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13159"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-86259",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "THU-MAIC",
      "product": "OpenMAIC",
      "cwe": "CWE-306",
      "title": "OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86259"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-19633",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DALIBO",
      "product": "PostgreSQL Anonymizer",
      "cwe": "CWE-89",
      "title": "PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain casts and view subqueries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19633"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2022-51009",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-248",
      "title": "PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51009"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-86250",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h3js",
      "product": "h3",
      "cwe": "CWE-400",
      "title": "h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86250"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-82750",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-1284",
      "title": "Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82750"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-82751",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-1284",
      "title": "Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82751"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-86251",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h3js",
      "product": "h3",
      "cwe": "CWE-22",
      "title": "h3 before 1.15.9 Path Traversal via Double Decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86251"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-86253",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h3js",
      "product": "h3",
      "cwe": "CWE-22",
      "title": "h3 before 1.15.6 Path Traversal via Percent-Encoded Dot Segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86253"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-86258",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter",
      "product": "nbviewer",
      "cwe": "CWE-22",
      "title": "nbviewer through 1.0.1 Path Traversal via LocalFileHandler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86258"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-86242",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maximhq",
      "product": "Bifrost",
      "cwe": "CWE-94",
      "title": "Unauthenticated RCE via Custom Plugin HTTP Path on Dynamically Linked Builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86242"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2020-37277",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-400",
      "title": "PocketMine-MP before 3.15.4 Denial of Service via InventoryTransaction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37277"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2021-48007",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-20",
      "title": "PocketMine-MP before 3.18.1 Denial of Service via MovePlayerPacket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-48007"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-86255",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-400",
      "title": "wger before 2.5 Uncontrolled Resource Consumption via date_sequence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86255"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-86283",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86283"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2022-51008",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-770",
      "title": "PocketMine-MP before 4.12.3 Denial of Service via Unauthenticated Sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51008"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-86252",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h3js",
      "product": "h3",
      "cwe": "CWE-74",
      "title": "h3 before 1.15.9 SSE Event Injection via Carriage Return",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86252"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-19859",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetFormBuilder",
      "cwe": "CWE-74",
      "title": "JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19859"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-19634",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DALIBO",
      "product": "PostgreSQL Anonymizer",
      "cwe": "CWE-89",
      "title": "PostgreSQL Anonymizer: SQL injection in import_database_rules() and import_roles_rules() via crafted object names / JSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19634"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-83534",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DALIBO",
      "product": "PostgreSQL Anonymizer",
      "cwe": "CWE-250",
      "title": "PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83534"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-86254",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-862",
      "title": "wger Incomplete Authorization Fix Cross-Tenant Account Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86254"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-86208",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System delete_teacher.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86208"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-86209",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System delete_user.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86209"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-86210",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System delete_user_account.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86210"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-86211",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabindralamsal",
      "product": "inventory-management-system",
      "cwe": "CWE-74",
      "title": "rabindralamsal inventory-management-system Login index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86211"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-86213",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mstfakts",
      "product": "College-Management-System",
      "cwe": "CWE-74",
      "title": "Mstfakts College-Management-System Search university.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86213"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-86214",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Mstfakts College-Management-System",
      "cwe": "CWE-287",
      "title": "Mstfakts College-Management-System login.php improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86214"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-86217",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hotel and Tourism Reservation in PHP",
      "cwe": "CWE-200",
      "title": "code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86217"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-86220",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System modal_add_course.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86220"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-86221",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System modal_add_course1.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86221"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-86222",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System modal_add_course2.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86222"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-86223",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System modal_add_coursea.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86223"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-86224",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System modal_add_product.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86224"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-86225",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System modal_add_room.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86225"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-86205",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h3js",
      "product": "h3",
      "cwe": "CWE-601",
      "title": "h3 before 2.0.1-rc.18 Open Redirect via redirectBack()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86205"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-86233",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-89",
      "title": "itsourcecode Sales and Inventory System us_del.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86233"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-86234",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-89",
      "title": "itsourcecode Sales and Inventory System cust_transac.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86234"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-86235",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-89",
      "title": "itsourcecode Sales and Inventory System pos_transac.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86235"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-86256",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-601",
      "title": "wger before 2.6 Open Redirect via trainer-login next parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86256"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2021-48006",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-178",
      "title": "PocketMine-MP before 4.0.3 Operator Privilege Escalation via Case Sensitivity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-48006"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-19862",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetFormBuilder",
      "cwe": "CWE-93",
      "title": "JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19862"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-80437",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ninja Forms",
      "cwe": "CWE-74",
      "title": "Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80437"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-80439",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Redirection for Contact Form 7",
      "cwe": "CWE-74",
      "title": "Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80439"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-86257",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-1236",
      "title": "wger before 2.6 CSV Formula Injection via member export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86257"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-86231",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwiede",
      "product": "jsch",
      "cwe": "CWE-298",
      "title": "mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86231"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-86212",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-266",
      "title": "Open5GS AMF/MME improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86212"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-86215",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mstfakts",
      "product": "College-Management-System",
      "cwe": "CWE-613",
      "title": "Mstfakts College-Management-System Logout server.php session expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86215"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-86216",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hotel and Tourism Reservation in PHP",
      "cwe": "CWE-79",
      "title": "code-projects Hotel and Tourism Reservation in PHP details.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86216"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-86228",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-266",
      "title": "JeecgBoot AiragModelController.java exportXls access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86228"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-86232",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System sup_del.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86232"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-86226",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Projectwolds",
      "product": "Online Attendance System",
      "cwe": "CWE-79",
      "title": "Projectwolds Online Attendance System profile.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86226"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-86227",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valkey-io",
      "product": "valkey",
      "cwe": "CWE-119",
      "title": "valkey-io valkey kvstore.c kvstoreGetHashtable out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86227"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-13608",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "OpenLDAP SASL authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13608"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-18924",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "HTTP/2 server push UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18924"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-19931",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "Negotiate ambient user conn reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19931"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-80229",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "OpenSSL provider use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80229"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-80230",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "OpenSSL pinning bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80230"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-80231",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "native CA store conn reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80231"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-80255",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "secure cookie attribute bypass with tab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80255"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-82208",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "wolfSSL CA-cache hit overrides callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82208"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-82209",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "curl",
      "product": "curl",
      "cwe": null,
      "title": "domain-scoped PSL domain cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82209"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-86219",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Authen-SASL",
      "cwe": "CWE-294",
      "title": "Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86219"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-86304",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "MojoX-Authentication",
      "cwe": "CWE-347",
      "title": "MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86304"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-15693",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-15693 (Unknown JCH Optimize). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-15694",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-15694 (Unknown Joli Table Of Contents). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-5914",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15247",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15247 (Unknown Search Atlas SEO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19858",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19858 (Unknown JetFormBuilder — Dynamic Blocks Form Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19861",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19861 (Unknown JetFormBuilder — Dynamic Blocks Form Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77826",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77826 (Unknown RegistrationMagic). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78149",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78149 (Unknown Smart Post). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78150",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78150 (Unknown Smart Post). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78362",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78362 (Unknown SEO Flow by LupsOnline). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81348",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81348 (Unknown My Private Site). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81404",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81404 (Unknown IPGP Visitors Origin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81423",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81423 (Unknown Accept Stripe Payments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81424",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81424 (Unknown Accept Stripe Payments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82304",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82304 (Unknown Music Store). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82846",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82846 (Unknown Masteriyo LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-83543",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-83543 (Unknown Greenshift). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-83544",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-83544 (Unknown Greenshift). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84021",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84021 (Unknown Bold Page Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84022",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84022 (Unknown Bold Page Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84221 (Unknown Kirki). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84225 (Unknown Kirki). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84745",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84745 (Unknown The Events Calendar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84896 (Unknown King Addons for Elementor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84898",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84898 (Unknown Eventin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84899 (Unknown VikWidgetsLoader). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84901",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84901 (Unknown Eventin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84926",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84926 (Unknown EmbedPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84927",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84927 (Unknown EmbedPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84930",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84930 (Unknown CatFolders Document Gallery & PDF Library). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84931",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84931 (Unknown Joli Table Of Contents). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84934",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84934 (Unknown JCH Optimize). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84935",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84935 (Unknown HT Menu). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84936",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84936 (Unknown EmbedPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84937",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84937 (Unknown Video Player for YouTube). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-49869",
      "detail": "DUE DATE PASSED — CVE-2026-49869 (kestra-io kestra). CISA remediation deadline was September 5, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-82329",
      "detail": "DUE DATE PASSED — CVE-2026-82329 (jfrog artifactory). CISA remediation deadline was September 5, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-83548",
      "detail": "DUE DATE PASSED — CVE-2026-83548 (SonicWall SMA1000). CISA remediation deadline was September 5, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-83549",
      "detail": "DUE DATE PASSED — CVE-2026-83549 (SonicWall SMA1000). CISA remediation deadline was September 5, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-9586",
      "detail": "DUE DATE PASSED — CVE-2026-9586 (Sangoma Switchvox SMB Edition). CISA remediation deadline was September 5, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
