{
  "day": "2026-09-07",
  "boundary": "UTC calendar day",
  "published_count": 252,
  "by_severity": {
    "CRITICAL": 13,
    "HIGH": 74,
    "MEDIUM": 119,
    "LOW": 42
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 4,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-79697",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.03353,
      "epss_percentile": 0.87899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "WISE-6610-NB",
      "cwe": "CWE-74",
      "title": "Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79697"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-79698",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.017,
      "epss_percentile": 0.75685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "WISE-6610-NB",
      "cwe": "CWE-74",
      "title": "Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79698"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-84732",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00544,
      "epss_percentile": 0.43747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-190",
      "title": "Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84732"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-86237",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00514,
      "epss_percentile": 0.41944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openagents-org",
      "product": "openagents",
      "cwe": "CWE-918",
      "title": "openagents-org openagents http.py test_default_model server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86237"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-86239",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00509,
      "epss_percentile": 0.41625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liufee",
      "product": "FeehiCMS",
      "cwe": "CWE-284",
      "title": "liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86239"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-86241",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00461,
      "epss_percentile": 0.38447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liufee",
      "product": "FeehiCMS",
      "cwe": "CWE-320",
      "title": "liufee FeehiCMS Cookie Validation main-local.php hard-coded key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86241"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-86260",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.36002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-620",
      "title": "sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86260"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-86274",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projeto-siga",
      "product": "siga",
      "cwe": "CWE-862",
      "title": "projeto-siga Authentication Flow ExAutenticacaoController.java ExAutenticacaoController.autenticar authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86274"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-86238",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00422,
      "epss_percentile": 0.35439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectworlds",
      "product": "Online Examination System",
      "cwe": "CWE-79",
      "title": "projectworlds Online Examination System Feedback Form feedback.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86238"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-86261",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00408,
      "epss_percentile": 0.34031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-285",
      "title": "sfturing hosp_order Order Controller OrderController.java authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86261"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-86262",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00408,
      "epss_percentile": 0.34032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-285",
      "title": "sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86262"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-86263",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00408,
      "epss_percentile": 0.34032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-285",
      "title": "sfturing hosp_order Order Cancellation OrderController.java orderRecordsService.cancelOrder authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86263"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-86289",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00399,
      "epss_percentile": 0.33233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Ollama",
      "cwe": "CWE-189",
      "title": "Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86289"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-84256",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-78",
      "title": "An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84256"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-86272",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.3144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Beijing Meite Software Technology",
      "product": "U+Smart Enjoyment WebSite",
      "cwe": "CWE-284",
      "title": "Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86272"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-86240",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00379,
      "epss_percentile": 0.31108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liufee",
      "product": "FeehiCMS",
      "cwe": "CWE-918",
      "title": "liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86240"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-84186",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.2791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrestaShop",
      "product": "PrestaShop",
      "cwe": "CWE-290",
      "title": "Incorrect access control in PrestaShop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84186"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-16876",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.25865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NEC Corporation",
      "product": "UNIVERGE IX-R/IX-V",
      "cwe": "CWE-306",
      "title": "An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16876"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-81738",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00331,
      "epss_percentile": 0.25817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-121",
      "title": "OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81738"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-86284",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.24784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaychouchannel",
      "product": "Tourism-Management-System",
      "cwe": "CWE-200",
      "title": "jaychouchannel Tourism-Management-System CommonController.java getOption information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86284"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-86277",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Syllabus-Aligned Learning Management & Examination System",
      "cwe": "CWE-285",
      "title": "SourceCodester Syllabus-Aligned Learning Management & Examination System delete_exam.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86277"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-86288",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00293,
      "epss_percentile": 0.21506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelCloud",
      "product": "GPTQModel",
      "cwe": "CWE-119",
      "title": "ModelCloud GPTQModel Triton dequantization kernel tritonv2.py out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86288"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-86273",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.2105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projeto-siga",
      "product": "siga",
      "cwe": "CWE-918",
      "title": "projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86273"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-86276",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Syllabus-Aligned Learning Management & Examination System",
      "cwe": "CWE-259",
      "title": "SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86276"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-86275",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.2078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Syllabus-Aligned Learning Management & Examination System",
      "cwe": "CWE-266",
      "title": "SourceCodester Syllabus-Aligned Learning Management & Examination System auth.php register privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86275"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-86244",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FastAdmin",
      "cwe": "CWE-79",
      "title": "FastAdmin User Controller User.php login cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86244"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-86278",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Syllabus-Aligned Learning Management & Examination System",
      "cwe": "CWE-79",
      "title": "SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86278"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-86282",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaychouchannel",
      "product": "Tourism-Management-System",
      "cwe": "CWE-74",
      "title": "jaychouchannel Tourism-Management-System CommonDao CommonController.java sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86282"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-86268",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.18773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "School Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode School Management System User_Login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86268"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-86290",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.18773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Voting System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Voting System ajax.php save_category sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86290"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-86342",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.18784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-862",
      "title": "MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86342"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-86264",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "ssm_pro",
      "cwe": "CWE-79",
      "title": "sfturing ssm_pro Order Endpoint OrderController.java cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86264"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-86271",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00232,
      "epss_percentile": 0.13934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FluentCMS",
      "cwe": "CWE-862",
      "title": "FluentCMS PermissionManager.cs GetAccessible authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86271"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-86279",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Syllabus-Aligned Learning Management & Examination System",
      "cwe": "CWE-384",
      "title": "SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86279"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-86285",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00222,
      "epss_percentile": 0.12676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "BookStack",
      "cwe": "CWE-266",
      "title": "BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86285"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-86280",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.11869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Syllabus-Aligned Learning Management & Examination System",
      "cwe": "CWE-310",
      "title": "SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86280"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-86332",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI (RHOAI)",
      "cwe": "CWE-862",
      "title": "Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86332"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-86269",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System emp_edit1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86269"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-20503",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-617",
      "title": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20503"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-20504",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-617",
      "title": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20504"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-20513",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.0985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-35",
      "title": "In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20513"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-86236",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System pro_transac.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86236"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-86245",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System sup_transac.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86245"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-86265",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System us_transac.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86265"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-86267",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.09892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Information System Society Membership System",
      "cwe": "CWE-74",
      "title": "itsourcecode Information System Society Membership System check_student.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86267"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-86270",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System settings_edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86270"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-78254",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0019,
      "epss_percentile": 0.08734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ant",
      "cwe": "CWE-23",
      "title": "Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78254"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-78043",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-22",
      "title": "The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78043"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-86281",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Syllabus-Aligned Learning Management & Examination System",
      "cwe": "CWE-352",
      "title": "SourceCodester Syllabus-Aligned Learning Management & Examination System cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86281"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-14297",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.04985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nordic Semiconductor ASA",
      "product": "nRF Connect SDK",
      "cwe": "CWE-787",
      "title": "The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14297"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-20501",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-122",
      "title": "In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20501"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-20502",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-122",
      "title": "In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20502"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-20515",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20515"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-84226",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-426",
      "title": "OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84226"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-20500",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-295",
      "title": "In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20500"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-20516",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-926",
      "title": "In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20516"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-20509",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-121",
      "title": "In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9011.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20509"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-20510",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-415",
      "title": "In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue ID: MSV-8894.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20510"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-20518",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20518"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-20506",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9126.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20506"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-20507",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9125.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20507"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-20508",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-843",
      "title": "In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9012.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20508"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-20511",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20511"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-20517",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20517"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-20514",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-307",
      "title": "In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632; Issue ID: MSV-8244.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20514"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-20512",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00126,
      "epss_percentile": 0.02596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-307",
      "title": "In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20512"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-86314",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Opensource",
      "product": "Walrus",
      "cwe": "CWE-190",
      "title": "Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86314"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-86315",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Opensource",
      "product": "Escargot",
      "cwe": "CWE-197",
      "title": "An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX. This issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86315"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-86313",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Opensource",
      "product": "Walrus",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86313"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-78221",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-131",
      "title": "An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78221"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-14296",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nordic Semiconductor ASA",
      "product": "nRF54H20",
      "cwe": "CWE-347",
      "title": "nRF54H20: MCUBoot can be tricked to executing unauthenticated code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14296"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-81830",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-73",
      "title": "The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81830"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-82312",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00101,
      "epss_percentile": 0.0098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-412",
      "title": "OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82312"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-18796",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00079,
      "epss_percentile": 0.00146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nordic Semiconductor ASA",
      "product": "nRF5340",
      "cwe": "CWE-1342",
      "title": "QSPI flash encryption side-channel leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18796"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-75650",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-1336",
      "title": "Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75650"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-7861",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Next4Biz Information Technologies Inc.",
      "product": "CSM (Customer Service Management)",
      "cwe": "CWE-502",
      "title": "Code Injection in Next4Biz's CSM (Customer Service Management)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7861"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-18922",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-287",
      "title": "389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18922"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-76578",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-306",
      "title": "Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76578"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-86478",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-290",
      "title": "In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86478"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-86480",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Hub",
      "cwe": "CWE-306",
      "title": "In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86480"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-6223",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bahçelievler Muncipality",
      "product": "BiHayat App",
      "cwe": "CWE-307",
      "title": "OTP Bypass in Bahçelievler Muncipality's BiHayat App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6223"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-61410",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-862",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended restrictions on code execution.Dell recommends customers to upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61410"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-80238",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-250",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80238"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-86296",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-822A",
      "cwe": "CWE-119",
      "title": "D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86296"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-86543",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-306",
      "title": "knowns before 0.30.0 Unauthenticated Management API Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86543"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-86426",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-287",
      "title": "LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86426"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-86404",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7",
      "cwe": "CWE-502",
      "title": "Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86404"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-86482",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-266",
      "title": "In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86482"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-86542",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-22",
      "title": "knowns before 0.30.0 Path Traversal via Import Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86542"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2022-51017",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-20",
      "title": "PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51017"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-19204",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Jetty",
      "cwe": "CWE-770",
      "title": "A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19204"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-86427",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "librenms",
      "product": "librenms",
      "cwe": "CWE-77",
      "title": "LibreNMS before 26.8.0 Argument Injection via graph_title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86427"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-86428",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-407",
      "title": "commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86428"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-86429",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-407",
      "title": "commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86429"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-86430",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-407",
      "title": "league/commonmark before 2.9.1 Denial of Service via parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86430"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-86433",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-407",
      "title": "commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86433"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-86434",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-407",
      "title": "commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86434"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-86435",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-407",
      "title": "commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86435"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-86439",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-22",
      "title": "knowns before 0.30.0 Path Traversal via MCP doc and memory tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86439"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-86452",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-400",
      "title": "MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86452"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-86538",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-22",
      "title": "knowns before 0.30.0 Path Traversal via templateFile parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86538"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-86299",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linksys",
      "product": "RE7000",
      "cwe": "CWE-77",
      "title": "Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86299"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-86437",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-863",
      "title": "Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86437"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-86438",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-862",
      "title": "Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86438"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-86492",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-488",
      "title": "In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86492"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-86540",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-78",
      "title": "knowns before 0.30.0 Arbitrary Code Execution via LSP Binary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86540"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-19843",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-78",
      "title": "389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19843"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-86502",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-306",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86502"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-84173",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Ankaios",
      "cwe": "CWE-863",
      "title": "In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by such a rule can submit a CompleteStateRequest or UpdateStateRequest with an empty field mask. The request may then be incorrectly authorized as matching the scoped rule, allowing the workload to read the complete cluster state or replace state outside its authorized subtree. This may result in unauthorized disclosure or modification of other workloads and cluster configuration. Only a rule consisting solely of * is intended to authorize an empty mask. Mitigation: Until an update containing the fix is installed, avoid multi-segment Control Interface allow-rule filter masks that begin with a wildcard, such as *.workloads.some_workload. Replace them with explicit paths such as desiredState.workloads.some_workload, where applicable. A filter mask consisting solely of * has different, intentionally unrestricted semantics and should only be used when full-state access is intended.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84173"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-79645",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-306",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79645"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-82586",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_lua",
      "cwe": "CWE-424",
      "title": "AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82586"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-82753",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_authentication_oauth2_server",
      "cwe": "CWE-770",
      "title": "Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82753"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-86297",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-605",
      "cwe": "CWE-189",
      "title": "D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86297"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-79678",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-95",
      "title": "Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79678"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-80132",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-306",
      "title": "ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80132"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-86479",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86479"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-80166",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-269",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80166"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-86504",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-829",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86504"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-80134",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-798",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80134"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-86494",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86494"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-86498",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86498"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-79639",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79639"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-6377",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Next4Biz Information Technologies Inc.",
      "product": "CSM (Customer Service Management)",
      "cwe": "CWE-22",
      "title": "Path Traversal in Next4Biz's CSM (Customer Service Management)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6377"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-14444",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Very Good Plugins",
      "product": "WP Fusion (Pro)",
      "cwe": "CWE-269",
      "title": "WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14444"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-18355",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-191",
      "title": "389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18355"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-18453",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-476",
      "title": "389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18453"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-76560",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-863",
      "title": "389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76560"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-78480",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-306",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78480"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-80135",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-703",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional Conditions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80135"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-79644",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79644"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-80131",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-22",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80131"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-80133",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-23",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80133"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-80164",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80164"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-61409",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) 5.0 Application",
      "cwe": "CWE-78",
      "title": "Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61409"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-79643",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-480",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Incorrect Operator vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79643"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-79691",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79691"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-6431",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor",
      "cwe": "CWE-79",
      "title": "User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6431"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-80127",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-78",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80127"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-86541",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-22",
      "title": "knowns before 0.30.0 Path Traversal via code.replace MCP action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86541"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-86544",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-863",
      "title": "knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86544"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2022-51010",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-20",
      "title": "PocketMine-MP before 4.4.2 Server Crash via Item ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51010"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2022-51012",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-20",
      "title": "PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51012"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2022-51013",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-20",
      "title": "PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51013"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2022-51014",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-248",
      "title": "PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51014"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2022-51015",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-20",
      "title": "PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51015"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2022-51018",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-400",
      "title": "PocketMine-MP before 3.26.5 Input Validation via Book Pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51018"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-80130",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-23",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80130"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-86347",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-400",
      "title": "MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86347"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-86408",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-639",
      "title": "MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected Events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86408"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-86419",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-200",
      "title": "MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86419"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-78325",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Standard Notes",
      "product": "Standard Notes",
      "cwe": "CWE-79",
      "title": "XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78325"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-86303",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "92181",
      "product": "markdown",
      "cwe": "CWE-119",
      "title": "92181 markdown md.c lds out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86303"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-86317",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-617",
      "title": "ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86317"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-86431",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-79",
      "title": "commonmark before 2.9.1 XSS via AttributesExtension form feed bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86431"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-86432",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thephpleague",
      "product": "commonmark",
      "cwe": "CWE-405",
      "title": "commonmark 2.0.0 before 2.8.4 Denial of Service via XML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86432"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-86539",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-918",
      "title": "knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86539"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-82325",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "ovpn-dco-win",
      "cwe": "CWE-415",
      "title": "A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82325"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-85201",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Ankaios",
      "cwe": "CWE-789",
      "title": "In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85201"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-86497",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-201",
      "title": "In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86497"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-12757",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icegram",
      "product": "Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress",
      "cwe": "CWE-94",
      "title": "Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12757"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-78488",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-78",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78488"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-80126",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-667",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80126"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-80129",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-22",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80129"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-80170",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-798",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80170"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-86488",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86488"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-86489",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86489"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-86490",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86490"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-86493",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86493"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-86495",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86495"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-2390",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codesupplyco",
      "product": "Powerkit – Supercharge your WordPress Site",
      "cwe": "CWE-79",
      "title": "Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Load Image Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2390"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-80128",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-287",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80128"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-77697",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Endpoint Central",
      "cwe": "CWE-269",
      "title": "Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77697"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-82754",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_authentication_oauth2_server",
      "cwe": "CWE-424",
      "title": "ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82754"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-82755",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_authentication_oauth2_server",
      "cwe": "CWE-524",
      "title": "ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82755"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-82756",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_authentication_oauth2_server",
      "cwe": "CWE-116",
      "title": "ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82756"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-82757",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_authentication_oauth2_server",
      "cwe": "CWE-918",
      "title": "ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82757"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-82758",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_authentication_oauth2_server",
      "cwe": "CWE-287",
      "title": "ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82758"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-85640",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Endpoint Central",
      "cwe": "CWE-269",
      "title": "Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85640"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-86420",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick before 7.1.2-30 Denial of Service Memory Budget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86420"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-86421",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick before 7.1.2-30 Memory Leak via MSL decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86421"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-79734",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79734"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-80125",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80125"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-86506",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "GoLand",
      "cwe": "CWE-306",
      "title": "In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86506"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-77698",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Endpoint Central",
      "cwe": "CWE-269",
      "title": "Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77698"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-79642",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79642"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-78487",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-321",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78487"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-79975",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-295",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to server-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79975"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-80054",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-732",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80054"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-80056",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-532",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80056"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-80057",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-321",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80057"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-80058",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-312",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80058"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-80167",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-321",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80167"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-80178",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-269",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80178"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-86292",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Traffic Offense System",
      "cwe": "CWE-287",
      "title": "SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86292"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-86293",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Traffic Offense System",
      "cwe": "CWE-287",
      "title": "SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86293"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-86295",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-895L",
      "cwe": "CWE-74",
      "title": "D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86295"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-86298",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System delete_subject.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86298"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-86300",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC9",
      "cwe": "CWE-287",
      "title": "Tenda AC9 Web Management R7WebsSecurityHandler improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86300"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-86302",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hospital Information System",
      "cwe": "CWE-200",
      "title": "code-projects Hospital Information System SQL Database Backup File his.sql information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86302"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-86305",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-284",
      "title": "light0011 cms Upload.class.php upload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86305"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-86306",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-287",
      "title": "light0011 cms Cookie Helper UserModel.class.php improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86306"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-86308",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-200",
      "title": "light0011 cms Debug Mode config.php information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86308"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-86318",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "java-json-tools",
      "product": "json-patch",
      "cwe": "CWE-119",
      "title": "java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fromJson stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86318"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-86319",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "java-json-tools",
      "product": "json-patch",
      "cwe": "CWE-400",
      "title": "java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86319"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-86321",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "java-json-tools",
      "product": "jackson-coreutils",
      "cwe": "CWE-918",
      "title": "java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.fromURL server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86321"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-86500",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-266",
      "title": "In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86500"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-12853",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rocklobsterinc",
      "product": "Flamingo",
      "cwe": "CWE-862",
      "title": "Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12853"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-86483",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86483"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2022-51011",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-20",
      "title": "PocketMine-MP before 4.2.10 Denial of Service via Chat Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51011"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2022-51016",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmmp",
      "product": "PocketMine-MP",
      "cwe": "CWE-294",
      "title": "PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-51016"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-4945",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE",
      "cwe": "CWE-639",
      "title": "Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4945"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-8279",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masteriyo",
      "product": "Masteriyo LMS – LMS Course Builder, Quizzes & Certificates",
      "cwe": "CWE-862",
      "title": "Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8279"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-86416",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ILIAS-eLearning e.V.",
      "product": "ILIAS",
      "cwe": "CWE-862",
      "title": "ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86416"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-86417",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-200",
      "title": "MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86417"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-86436",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-862",
      "title": "Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86436"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-86451",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-639",
      "title": "MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86451"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-86469",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-59",
      "title": "Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86469"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-86351",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86351"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-86440",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86440"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-77699",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Endpoint Central",
      "cwe": "CWE-269",
      "title": "Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77699"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-79943",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-297",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79943"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-86423",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick before 7.1.2-30 Heap-use-after-free via GetList",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86423"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-86425",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick before 7.1.2-30 Heap-use-after-free via Layer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86425"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-80176",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway 5.0 - Application",
      "cwe": "CWE-257",
      "title": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80176"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-86484",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86484"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-86481",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86481"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-86496",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86496"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-86499",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86499"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-86486",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-306",
      "title": "In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86486"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2025-52651",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "MyXalytics",
      "cwe": "CWE-20",
      "title": "HCL MyXalytics is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52651"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2025-52652",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "MyXalytics",
      "cwe": "CWE-451",
      "title": "HCL MyXalytics is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52652"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2025-52657",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "MyXalytics",
      "cwe": "CWE-770",
      "title": "HCL MyXalytics is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52657"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-86491",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86491"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-86485",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-291",
      "title": "In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86485"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-86503",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-918",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86503"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-86505",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-201",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86505"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-86487",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86487"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-86501",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-532",
      "title": "In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86501"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-82584",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "igniter",
      "cwe": "CWE-150",
      "title": "Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82584"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-86418",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-200",
      "title": "MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86418"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-86441",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-200",
      "title": "MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86441"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-81638",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_double_entry",
      "cwe": "CWE-173",
      "title": "Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81638"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-86291",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System us_edit1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86291"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-86294",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Traffic Offense System",
      "cwe": "CWE-79",
      "title": "SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86294"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-86307",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "light0011",
      "product": "cms",
      "cwe": "CWE-352",
      "title": "light0011 cms cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86307"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-86309",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System pro_searchfrm.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86309"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-86310",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System cust_edit1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86310"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-86301",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hospital Information System",
      "cwe": "CWE-79",
      "title": "code-projects Hospital Information System Patient Management editPatient.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86301"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-86424",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-59",
      "title": "ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86424"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-86422",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-59",
      "title": "ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86422"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-16028",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Protocol-HTTP2",
      "cwe": "CWE-401",
      "title": "Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16028"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-86287",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IP-LPM",
      "cwe": "CWE-1287",
      "title": "Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86287"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-5914",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62718",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62718 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-69534",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-69534. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-23745",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-23745 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24842 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25639 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-30922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32286",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40175",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40175 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41242",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42033 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42039 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42041 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42043",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42043 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42044 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42264 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42578 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42579 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42584 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42880",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42880 (argoproj argo-cd). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42945",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43997 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43998 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43999",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43999 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44005",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44005 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44007 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44009",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44009 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44486 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44487 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44488 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44494 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45411 (patriksimek vm2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45736",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67276",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67276 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67278 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67281",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67281 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-2670",
      "detail": "RESCORED — CVE-2026-2670 (Advantech WISE-6610-NB). CVSS 8.6 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-86233",
      "detail": "RESCORED — CVE-2026-86233 (itsourcecode Sales and Inventory System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-86234",
      "detail": "RESCORED — CVE-2026-86234 (itsourcecode Sales and Inventory System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-86235",
      "detail": "RESCORED — CVE-2026-86235 (itsourcecode Sales and Inventory System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16118",
      "detail": "PATCH SHIPPED — CVE-2026-16118 (xdgmime). Fixed in Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.22."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-63622",
      "detail": "PATCH SHIPPED — CVE-2026-63622 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:10.10.0-8.11.el10_0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-78701",
      "detail": "PATCH SHIPPED — CVE-2026-78701 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.2.0-10.el10_2."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-21817",
      "detail": "ENRICHED — CVE-2025-21817 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-22127",
      "detail": "ENRICHED — CVE-2025-22127 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-38205",
      "detail": "ENRICHED — CVE-2025-38205 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-38621",
      "detail": "ENRICHED — CVE-2025-38621 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43344",
      "detail": "ENRICHED — CVE-2026-43344 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
