{
  "day": "2026-09-10",
  "boundary": "UTC calendar day",
  "published_count": 384,
  "by_severity": {
    "CRITICAL": 59,
    "HIGH": 170,
    "MEDIUM": 135,
    "LOW": 7
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 13,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-0302",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00824,
      "epss_percentile": 0.55217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Checkov by Prisma Cloud",
      "cwe": "CWE-78",
      "title": "Checkov by Prisma Cloud: OS Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0302"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-18351",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00768,
      "epss_percentile": 0.53444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "addonsorg",
      "product": "Drag and Drop File Upload for Elementor Forms",
      "cwe": "CWE-434",
      "title": "Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18351"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-18386",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00746,
      "epss_percentile": 0.52707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cssimmon",
      "product": "WP BackItUp Community Edition",
      "cwe": "CWE-22",
      "title": "WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18386"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-15019",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00676,
      "epss_percentile": 0.5016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kamalyon",
      "product": "Direct Download for WooCommerce",
      "cwe": "CWE-22",
      "title": "Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15019"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-19583",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.006,
      "epss_percentile": 0.46786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-732",
      "title": "Velociraptor Required Permissions bypass by using client monitoring queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19583"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-78374",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00538,
      "epss_percentile": 0.43597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlart.com",
      "product": "T4 Page Builder extension for Joomla",
      "cwe": "CWE-201",
      "title": "Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78374"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-78082",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0049,
      "epss_percentile": 0.40578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Property extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78082"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-0309",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00447,
      "epss_percentile": 0.37701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-78",
      "title": "PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0309"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-44950",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Container suse/kiosk/tigervnc-x11vnc:1.14-63.8",
      "cwe": "CWE-122",
      "title": "fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44950"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-78302",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Property extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78302"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-84063",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-ZERO CO.,LTD.",
      "product": "BurgerEditor",
      "cwe": "CWE-434",
      "title": "BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84063"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-78303",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.36075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Property extension for Joomla",
      "cwe": "CWE-201",
      "title": "Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78303"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-59679",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Container suse/kiosk/tigervnc-x11vnc:1.14-63.8",
      "cwe": "CWE-787",
      "title": "fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59679"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-88273",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-78",
      "title": "GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88273"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-88274",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-78",
      "title": "GV-LPC2011/LPC2211 - Wireless SSID Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88274"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-88275",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-78",
      "title": "GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88275"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-88276",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-78",
      "title": "GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88276"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-88288",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-36",
      "title": "GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88288"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-88277",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-78",
      "title": "GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88277"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-0310",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.2676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-787",
      "title": "PAN-OS: Buffer Overflow Vulnerability via XML Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0310"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-5399",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "Redux Framework",
      "cwe": "CWE-79",
      "title": "Redux Framework <= 4.5.13.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5399"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-88289",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88289"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-78084",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Property extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78084"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-7188",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armiya Information Technologies Ltd. Co.",
      "product": "Access Control System",
      "cwe": "CWE-89",
      "title": "SQLi in Armiya Information Technologies' Access Control System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7188"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-88287",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.23989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88287"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-87803",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Countly",
      "product": "countly-server",
      "cwe": "CWE-863",
      "title": "An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWN_STAGE_OPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $_internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87803"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-87933",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaveGamble",
      "product": "cJSON",
      "cwe": "CWE-119",
      "title": "DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87933"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-88272",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-78",
      "title": "GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88272"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-88282",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-78",
      "title": "GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88282"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-13745",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00299,
      "epss_percentile": 0.22393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Gemini CLI",
      "cwe": "CWE-20",
      "title": "Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13745"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-84062",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-ZERO CO.,LTD.",
      "product": "BurgerEditor",
      "cwe": "CWE-639",
      "title": "BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84062"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-67593",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.21223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis",
      "cwe": "CWE-306",
      "title": "Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67593"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-82925",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.2119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Site Reviews",
      "cwe": "CWE-502",
      "title": "Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82925"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-49363",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.20973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis",
      "cwe": "CWE-306",
      "title": "Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49363"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-57967",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00279,
      "epss_percentile": 0.2021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis",
      "cwe": "CWE-306",
      "title": "Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57967"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-88285",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-306",
      "title": "GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88285"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-88278",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.18858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-294",
      "title": "GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88278"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-0308",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00265,
      "epss_percentile": 0.18356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-79",
      "title": "PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0308"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-88286",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-400",
      "title": "GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88286"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-88290",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-400",
      "title": "GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88290"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-8323",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00254,
      "epss_percentile": 0.16868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armiya Information Technologies Ltd. Co.",
      "product": "Access Control System",
      "cwe": "CWE-601",
      "title": "Open Redirect in Armiya Information Technologies' Access Control System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8323"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-42804",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.16863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch Sensortec",
      "product": "BHI360_SensorAPI (C-Library)",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875). The parser trusts the first payload byte of a debug frame as the message length (msg_length) and copies that many bytes into a fixed-size 17-byte stack buffer (debug_msg) via memcpy without performing any bounds checking. A locally or physically positioned attacker (e.g., via a malicious sensor, counterfeit hardware module, or a Man-in-the-Middle on the communication bus) can exploit this vulnerability by injecting a crafted debug frame with a length byte exceeding 16. This corrupts adjacent stack data, including the saved return address. Furthermore, because the overflowed buffer is subsequently passed to a printf-style logging sink, the attacker can supply format string specifiers (e.g., %n) to execute arbitrary code on the host microcontroller/SoC or cause a reliable system crash (Denial of Service).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42804"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-88279",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88279"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-88280",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88280"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-88281",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88281"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-88283",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88283"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-88284",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211 -",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88284"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-15889",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arubadev",
      "product": "Aruba HiSpeed Cache",
      "cwe": "CWE-79",
      "title": "Aruba HiSpeed Cache <= 3.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15889"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-88763",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Service Interconnect 2",
      "cwe": "CWE-674",
      "title": "Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88763"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-4657",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sunny_johal",
      "product": "Easy Google Fonts",
      "cwe": "CWE-79",
      "title": "Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4657"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-88268",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.14831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - SSVR Fragment-Reassembly Stack Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88268"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-76562",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "otwthemes",
      "product": "Sidebar Manager Light",
      "cwe": "CWE-79",
      "title": "Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_description' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76562"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-14873",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.1447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rubenw",
      "product": "Bulk Password Reset",
      "cwe": "CWE-862",
      "title": "Bulk Password Reset <= 1.3.3 - Authenticated (Subscriber+) Arbitrary Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14873"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-88271",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-862",
      "title": "GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88271"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-49362",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis",
      "cwe": "CWE-306",
      "title": "Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49362"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-0304",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cortex XDR Broker VM",
      "cwe": "CWE-88",
      "title": "Cortex XDR Broker VM: Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0304"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-85645",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.11873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder",
      "cwe": "CWE-79",
      "title": "Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85645"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-88770",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-307",
      "title": "Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-force-locked accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88770"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-18594",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vsourz1td",
      "product": "Advanced Contact form 7 DB",
      "cwe": "CWE-862",
      "title": "Advanced Contact form 7 DB <= 2.1.3 - Missing Authorization to Authenticated (Custom+) Unauthorized Data Import via 'import_cf7_id'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18594"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-84939",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00212,
      "epss_percentile": 0.11457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache FreeMarker",
      "cwe": "CWE-23",
      "title": "Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84939"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-88270",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-862",
      "title": "GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88270"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-87870",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.10808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saturday Drive",
      "product": "Ninja Forms - Scheduled Exports",
      "cwe": "CWE-79",
      "title": "Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87870"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-15823",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.10884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "builderall",
      "product": "Builderall for WordPress",
      "cwe": "CWE-862",
      "title": "Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15823"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-78083",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Property extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78083"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-42807",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch Sensortec",
      "product": "COINES_SDK",
      "cwe": "CWE-122",
      "title": "A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue_add_data}}) without validating the bounds of the destination buffer. A malicious or compromised USB or Bluetooth Low Energy (BLE) peripheral can advertise a payload size up to ~3 KB, which exceeds the default queue slot size of 255 bytes. This results in an unbounded heap overwrite ({{memcpy}}), corrupting adjacent heap metadata on the host system when processing the device's response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42807"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-88269",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.1,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPC2011/LPC2211",
      "cwe": "CWE-862",
      "title": "GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88269"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-15820",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "builderall",
      "product": "Builderall for WordPress",
      "cwe": "CWE-79",
      "title": "Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Module 'attributes' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15820"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-82582",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.09964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SHIRASAGI Project",
      "product": "SHIRASAGI",
      "cwe": "CWE-639",
      "title": "An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82582"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-15796",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "builderall",
      "product": "Builderall for WordPress",
      "cwe": "CWE-79",
      "title": "Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15796"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-42808",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.08792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch Sensortec",
      "product": "COINES_SDK",
      "cwe": "CWE-120",
      "title": "An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11. The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Internally, the stream processing mechanism in {{comm_intf_process_stream_response()}} discards the requested {{number_of_samples}} argument and copies the entirety of the streaming ring buffer's accumulated data into {{coines_stream_rsp_buf}}. Subsequently, {{coines_read_stream_sensor_data()}} unconditionally executes a {{memcpy}} of the ring buffer size into the caller-provided buffer without verifying if the destination memory allocation is large enough. A malicious or compromised hardware board connected via USB or BLE can exploit this by streaming a high volume of sensor samples, causing a heap or stack-based buffer overflow on the host desktop environment. This can result in a Denial of Service (DoS) or potential arbitrary code execution on the host machine.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42808"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-19584",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.0873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-94",
      "title": "Velociraptor VQL injection during notebook restore from backup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19584"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-80351",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00182,
      "epss_percentile": 0.07872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel K",
      "cwe": "CWE-95",
      "title": "Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80351"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-57822",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis",
      "cwe": "CWE-502",
      "title": "Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57822"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-80352",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00164,
      "epss_percentile": 0.05875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel K",
      "cwe": "CWE-94",
      "title": "Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80352"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-49364",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00162,
      "epss_percentile": 0.0575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis",
      "cwe": "CWE-306",
      "title": "Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49364"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-75880",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis",
      "cwe": "CWE-1333",
      "title": "Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75880"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-82079",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.0519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nintendo",
      "product": "Nintendo Switch",
      "cwe": "CWE-121",
      "title": "Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82079"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-42806",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.04801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch Sensortec",
      "product": "BME690 SensorAPI (C)",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior, specifically within the field data parsing logic in read_all_field_data (bme69x.c). The driver prefetches heater configuration registers into a contiguous 30-byte stack buffer (set_val) mapping IDAC, RES_HEAT, and GAS_WAIT tables. When parsing sensor field data, the gas_index is extracted using a 4-bit mask (0..15) but lacks boundary verification against the valid range (0..9). An attacker or a compromised peripheral mimicking a sensor on the I2C/SPI bus could return a payload with a gas index value of 10 or higher. This causes the driver to perform an out-of-bounds array access (set_val[20 + gas_index]), reading up to 6 bytes past the stack buffer. The leaked out-of-bounds byte is then written into the public gas_wait field, which may lead to measurement corruption or leak adjacent stack memory when telemetered or logged.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42806"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-81635",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SHIRASAGI Project",
      "product": "SHIRASAGI",
      "cwe": "CWE-79",
      "title": "A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81635"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-19439",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Gift Cards for WooCommerce",
      "cwe": "CWE-200",
      "title": "Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19439"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-42805",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch Sensortec",
      "product": "BHI385 SensorAPI (C Library)",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event payload (callback_info->data_ptr[0]) without enforcing bounds checks or clamping the value. When copying the payload into a fixed-size stack buffer of 17 bytes (uint8_t debug_msg[17]) via memcpy, providing a length byte greater than 16 causes the function to write past the allocated stack boundary. This memory corruption can be triggered by a malicious or compromised sensor or bus participant, leading to a firmware crash, Denial of Service (DoS), or potentially the execution of arbitrary code via adjacent stack data corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42805"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-80354",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.0369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel K",
      "cwe": "CWE-639",
      "title": "Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80354"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-78361",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "zipMoney(Zip Co) Payments Plugin for WooCommerce",
      "cwe": "CWE-862",
      "title": "zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Option Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78361"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-19436",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Gift Cards for WooCommerce",
      "cwe": "CWE-284",
      "title": "Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation via Discounted Purchase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19436"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-77770",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00132,
      "epss_percentile": 0.03105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "miniOrange 2FA",
      "cwe": "CWE-862",
      "title": "miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77770"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-77771",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "miniOrange 2FA",
      "cwe": "CWE-287",
      "title": "miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77771"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-81431",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Registration Form for WooCommerce",
      "cwe": "CWE-269",
      "title": "Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81431"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-19840",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Notiqoo",
      "cwe": "CWE-863",
      "title": "Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19840"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-0303",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00128,
      "epss_percentile": 0.02812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Checkov by Prisma Cloud",
      "cwe": "CWE-829",
      "title": "Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0303"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-88265",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-59",
      "title": "Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88265"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-88264",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-59",
      "title": "Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88264"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-0307",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.0116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "GlobalProtect App",
      "cwe": "CWE-426",
      "title": "GlobalProtect App: Local Privilege Escalation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0307"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-0306",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-693",
      "title": "Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0306"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-84042",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-269",
      "title": "Crun: crun: rootful krun with passt executes container payload as host root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84042"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-0305",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-200",
      "title": "Prisma Access Agent: Information Disclosure Vulnerability on Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0305"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-68487",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-36",
      "title": "Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68487"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-68488",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-367",
      "title": "A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68488"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-89094",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forgejo",
      "product": "Forgejo",
      "cwe": "CWE-1336",
      "title": "Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89094"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-9163",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIS Informatics",
      "product": "GisLab Laboratory Management System",
      "cwe": "CWE-89",
      "title": "SQLi in GIS Informatics' GisLab Laboratory Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9163"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-52098",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52098"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-78573",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "ContextForge MCP Gateway",
      "cwe": "CWE-1392",
      "title": "IBM ContextForge MCP Gateway is affected by use of default credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78573"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-79724",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79724"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-81204",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81204"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-81467",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-78",
      "title": "Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81467"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-85025",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-863",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85025"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-88018",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-287",
      "title": "rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88018"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-81048",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-77",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81048"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-82100",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82100"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-82107",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-287",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82107"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-65639",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "ConfigServer Security & Firewall",
      "cwe": "CWE-78",
      "title": "OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65639"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-88062",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "diegosouzapw",
      "product": "OmniRoute",
      "cwe": "CWE-94",
      "title": "OmniRoute ACP Custom-Agent Remote Code Execution (RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88062"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-81046",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-284",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81046"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-75940",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Health Application",
      "cwe": "CWE-798",
      "title": "A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75940"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-81800",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Par avisverifies",
      "product": "Verified Reviews (Avis Vérifiés)",
      "cwe": "CWE-89",
      "title": "WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81800"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-88860",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo.app",
      "cwe": "CWE-863",
      "title": "Capgo Authorization Bypass via Stale Channel Permission Overrides",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88860"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-88864",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo.app",
      "cwe": "CWE-284",
      "title": "Capgo SSO Provider Authentication Bypass via PostgREST Direct Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88864"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-88866",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo LoginControl Stored XSS via User-Agent Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88866"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-88867",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Stored XSS via Category Name and Icon Class",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88867"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-88868",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo LiveLinks Stored XSS via title and description fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88868"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-88869",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo AD_Server Stored XSS via log.php label parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88869"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-88877",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-639",
      "title": "Traefik v3.7.0 Authentication Bypass via from-to-www-redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88877"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-88899",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-73",
      "title": "knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88899"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-89042",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krakenjs",
      "product": "passport-saml-encrypted",
      "cwe": "CWE-347",
      "title": "passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89042"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-65638",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "ConfigServer Security & Firewall",
      "cwe": "CWE-78",
      "title": "Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65638"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-88880",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-601",
      "title": "Renovate before 44.11.3 Credential Exfiltration via Link Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88880"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-88881",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-601",
      "title": "Renovate before 44.11.3 Credential Exfiltration via Link Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88881"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-88882",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-601",
      "title": "Renovate before 44.11.2 Credential Exfiltration via Link Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88882"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-88887",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-601",
      "title": "Renovate before 44.11.2 Credential Exfiltration via Link Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88887"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-19646",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-1149",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19646"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-45764",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-843",
      "title": "Suricata http2: protocol-change type confusion can lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45764"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-80424",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80424"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-81468",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-78",
      "title": "Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81468"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-88007",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-287",
      "title": "Traefik HTTP/3 Backend NTLM Connection Reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88007"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-88044",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-863",
      "title": "rclone: RC per-server auth-proxy bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88044"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-89043",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krakenjs",
      "product": "passport-saml-encrypted",
      "cwe": "CWE-347",
      "title": "passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89043"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-89086",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OCaml",
      "product": "jose",
      "cwe": "CWE-347",
      "title": "In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89086"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-75624",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-863",
      "title": "IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75624"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-75777",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera Enterprise WebApps",
      "cwe": "CWE-269",
      "title": "Multiple vulnerabilities in IBM Aspera Enterprise Webapps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75777"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-76059",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-693",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76059"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-78569",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78569"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-78571",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78571"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-78575",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78575"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-79742",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79742"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-81211",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-862",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81211"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-81550",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81550"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-81551",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81551"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-81554",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81554"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-81940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81940"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-81941",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-284",
      "title": "Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81941"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-82092",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-36",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82092"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-82095",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82095"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-82097",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-918",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82097"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-82098",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82098"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-82099",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82099"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-84889",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84889"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-85228",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "Deep Java Library",
      "cwe": "CWE-190",
      "title": "Integer overflow in tensor buffer validation in Deep Java Library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85228"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-88009",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-444",
      "title": "Traefik: Rootless HTTP/1 request-target routes as \"/\" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88009"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-89046",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "luben",
      "product": "zstd-jni",
      "cwe": "CWE-125",
      "title": "zstd-jni 1.5.5-6 through 1.5.7-13 Out-of-Bounds Read via Negative Offset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89046"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-16174",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netskope",
      "product": "Endpoint DLP",
      "cwe": "CWE-190",
      "title": "Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16174"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-64836",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ICEcoder",
      "product": "ICEcoder",
      "cwe": "CWE-22",
      "title": "ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64836"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-64837",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ICEcoder",
      "product": "ICEcoder",
      "cwe": "CWE-78",
      "title": "ICEcoder through 8.1 OS Command Injection via lib/properties.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64837"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-64838",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ICEcoder",
      "product": "ICEcoder",
      "cwe": "CWE-22",
      "title": "ICEcoder through 8.1 Path Traversal via oldFileName Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64838"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-73693",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FileRun",
      "product": "FileRun",
      "cwe": "CWE-78",
      "title": "FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73693"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-75584",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nasa-jpl",
      "product": "ION-DTN",
      "cwe": "CWE-617",
      "title": "ION-DTN < 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75584"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-79987",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-470",
      "title": "Low-privilege RCE through element-search eager loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79987"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-87962",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tdunning",
      "product": "t-digest",
      "cwe": "CWE-1284",
      "title": "t-digest 3.1 through 3.3 Denial of Service via Unvalidated Length Fields in MergingDigest.fromBytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87962"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-88861",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo.app",
      "cwe": "CWE-288",
      "title": "Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88861"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-88862",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo.app",
      "cwe": "CWE-863",
      "title": "Capgo API Key Manager Authentication Bypass via x-limited-key-id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88862"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-88874",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88874"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-88876",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88876"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-88893",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-200",
      "title": "OpenPanel Unauthenticated Share Lookup Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88893"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-88939",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-863",
      "title": "knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88939"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-88959",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anchorcms",
      "product": "Anchor CMS",
      "cwe": "CWE-862",
      "title": "Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88959"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-4129",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "SystemLink",
      "cwe": "CWE-862",
      "title": "Improper Access Controls in NI SystemLink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4129"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-73694",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FileRun",
      "product": "FileRun",
      "cwe": "CWE-78",
      "title": "FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73694"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-73698",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FileRun",
      "product": "FileRun",
      "cwe": "CWE-89",
      "title": "FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73698"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-73699",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FileRun",
      "product": "FileRun",
      "cwe": "CWE-502",
      "title": "FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73699"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-81213",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81213"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-81789",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Maarten B",
      "product": "Advanced Product Fields Extended for WooCommerce",
      "cwe": "CWE-22",
      "title": "WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81789"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-85217",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Fusion",
      "cwe": "CWE-15",
      "title": "Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85217"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-88047",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-121",
      "title": "Tesseract: ReadNormProtos stack buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88047"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-88048",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-125",
      "title": "Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88048"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-88049",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-787",
      "title": "Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88049"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-88051",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-787",
      "title": "Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88051"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-88053",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-787",
      "title": "Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted .traineddata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88053"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-88056",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-918",
      "title": "Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88056"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-88058",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88058"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-88060",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88060"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-88863",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo.app",
      "cwe": "CWE-269",
      "title": "capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88863"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-88865",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "AVideo Missing Authorization via getRestream.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88865"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-88895",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-287",
      "title": "CyberPanel before 3.0.5 Authentication Bypass via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88895"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-88937",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-22",
      "title": "knowns through 0.33.0 Path Traversal via Template Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88937"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-11813",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "FileZ Client",
      "cwe": "CWE-276",
      "title": "A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11813"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-63427",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Software Fix",
      "cwe": "CWE-290",
      "title": "An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63427"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-80378",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-285",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80378"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-80436",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-285",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80436"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-81207",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-918",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81207"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-81540",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81540"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-88886",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-78",
      "title": "Renovate before 44.14.7 Command Injection via gradle-wrapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88886"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-88889",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-78",
      "title": "Renovate before 44.14.7 Command Injection via distributionType",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88889"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-89049",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amazon SSM Agent",
      "cwe": "CWE-918",
      "title": "Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89049"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-4130",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "SystemLink",
      "cwe": "CWE-312",
      "title": "Storage of Sensitive Information in Cleartext in NI SystemLink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4130"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-18994",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "File Manager Application",
      "cwe": "CWE-926",
      "title": "A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18994"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-19136",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Tianxi AI Agent PC Application",
      "cwe": "CWE-78",
      "title": "A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19136"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-88022",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Laravel MongoDB (PHP)",
      "cwe": "CWE-943",
      "title": "Unauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for Laravel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88022"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-88890",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-89",
      "title": "OpenPanel SQL Injection via unvalidated profile filter column identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88890"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-87090",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-863",
      "title": "Consul vulnerable to an authorization bypass in the catalog node-write path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87090"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-88883",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-532",
      "title": "Renovate before 44.14.4 TLS Private Key Log Sanitisation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88883"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-88032",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Java Driver",
      "cwe": "CWE-416",
      "title": "Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88032"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-88897",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flextype",
      "product": "flextype",
      "cwe": "CWE-598",
      "title": "Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88897"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-89054",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The OpenNMS Group",
      "product": "Horizon",
      "cwe": "CWE-862",
      "title": "OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89054"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-81268",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-613",
      "title": "Langflow is vulnerable to authentication bypass and insufficient session expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81268"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-81784",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Marcin",
      "product": "Wise Chat",
      "cwe": "CWE-502",
      "title": "WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81784"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-81801",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UDX Usability Dynamics",
      "product": "WP-Stateless",
      "cwe": "CWE-862",
      "title": "WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81801"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-81805",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SiteSkite",
      "product": "SiteSkite",
      "cwe": "CWE-266",
      "title": "WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81805"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-87958",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-269",
      "title": "IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87958"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-2310",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "webMethods Integration Server",
      "cwe": "CWE-91",
      "title": "IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2310"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-88052",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-129",
      "title": "Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynchronization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88052"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-17176",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Deco BE11000 V2",
      "cwe": "CWE-78",
      "title": "OS command injection Vulnerability in Deco BE11000",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17176"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-81210",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-639",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81210"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-87993",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-532",
      "title": "Consul-template vulnerable to an information disclosure issue in error handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87993"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-6285",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ankaref Innovation and Technology Inc.",
      "product": "LIBRID/LIBREF",
      "cwe": "CWE-640",
      "title": "Improper Authentication in Ankaref's LIBRID/LIBREF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6285"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-9166",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIS Informatics",
      "product": "GisLab Laboratory Management System",
      "cwe": "CWE-22",
      "title": "LFI in GIS Informatics' GisLab Laboratory Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9166"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-45747",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-476",
      "title": "Suricata lua/tls: null dereference in TlsGetCertInfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45747"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-45759",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata http1: quadratic Content-Disposition processing can lead to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45759"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-45762",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-843",
      "title": "Suricata defrag: missing address-family check can lead to remote crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45762"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-45765",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata dnp3: unbounded reassembly can lead to resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45765"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-45766",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata nfs: unbounded stateful structures can lead to resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45766"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-45768",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata ldap: unbounded responses per transaction can lead to resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45768"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-45769",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "ikev2: unbounded client transform storage can lead to resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45769"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-45770",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-693",
      "title": "Suricata lua: excessive flow variable registration can bypass sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45770"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-46387",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-409",
      "title": "Suricata http2: decompression bomb can cause denial of service in Suricata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46387"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-77807",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acyba",
      "product": "AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress",
      "cwe": "CWE-22",
      "title": "AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77807"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-81265",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81265"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-81786",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Thank You Page Customizer for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81786"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-81794",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlfactory",
      "product": "Shirt Product Designer for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81794"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-81799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Return Refund and Exchange For WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81799"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-81803",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ateeq Rafeeq",
      "product": "RepairBuddy",
      "cwe": "CWE-94",
      "title": "WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81803"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-81804",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zain Hassan",
      "product": "ZHBackup – Backup, Restore &amp; Migration",
      "cwe": "CWE-201",
      "title": "WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81804"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-84821",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Epsiloncool",
      "product": "WP Fast Total Search",
      "cwe": "CWE-862",
      "title": "WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84821"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-86093",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-121",
      "title": "IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86093"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-88045",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-789",
      "title": "rclone: S3 multipart declared-length memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88045"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-80434",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-639",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80434"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-81796",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Travel",
      "product": "WP Travel",
      "cwe": "CWE-288",
      "title": "WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81796"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-88017",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-488",
      "title": "rclone: FTP cross-session auth-proxy backend confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88017"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-88885",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-78",
      "title": "Renovate before 44.14.7 Command Injection via depName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88885"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-88888",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-78",
      "title": "Renovate before 44.14.7 Command Injection via Mix organization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88888"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-89087",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OCaml",
      "product": "cstruct",
      "cwe": "CWE-573",
      "title": "The cstruct package before 6.3.0 for OCaml mishandles indexes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89087"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-88891",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-269",
      "title": "OpenPanel Read-Only Access Level Enforcement Bypass via Mutations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88891"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-80380",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-352",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80380"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-81783",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mailmunch",
      "product": "MailMunch – Grow your Email List",
      "cwe": "CWE-288",
      "title": "WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81783"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-81795",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Denis Botić",
      "product": "Page Visits Counter &#8211; Lite",
      "cwe": "CWE-79",
      "title": "WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81795"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-84816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "WPCS",
      "cwe": "CWE-79",
      "title": "WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84816"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-84819",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Greg Winiarski",
      "product": "WPAdverts",
      "cwe": "CWE-79",
      "title": "WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84819"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-85545",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "HikCentral Access Control",
      "cwe": "CWE-284",
      "title": "There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85545"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-87961",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "schreibfaul1",
      "product": "ESP32-audioI2S",
      "cwe": "CWE-125",
      "title": "ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87961"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-88016",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-59",
      "title": "rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88016"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-88021",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-185",
      "title": "Consul vulnerable to an authorization bypass in the Connect service mesh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88021"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-88026",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C# Driver",
      "cwe": "CWE-943",
      "title": "Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88026"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-88027",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Laravel MongoDB (PHP)",
      "cwe": "CWE-943",
      "title": "Mass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB integration for Laravel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88027"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-88028",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Laravel MongoDB (PHP)",
      "cwe": "CWE-943",
      "title": "Unauthorized document disclosure via query-operator injection in polymorphic relation identifiers in MongoDB integration for Laravel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88028"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-88870",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo LoginControl PGP Key CSRF via GET Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88870"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-88872",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "AVideo CustomizeUser setPassword.json.php CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88872"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-88873",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo Cross-Site Request Forgery via logArchive.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88873"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-88898",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AppFlowy-IO",
      "product": "AppFlowy-Cloud",
      "cwe": "CWE-862",
      "title": "AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88898"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-88915",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-862",
      "title": "MISP Event Template Instantiation Bypasses Sharing Group and Tagging Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88915"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-88938",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-22",
      "title": "knowns through 0.33.0 Path Traversal via code.find MCP tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88938"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-89011",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isomorphic-git",
      "product": "isomorphic-git",
      "cwe": "CWE-1321",
      "title": "isomorphic-git < 1.42.0 Prototype Pollution via getRemoteInfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89011"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-15419",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "silabser.sys driver",
      "cwe": "CWE-121",
      "title": "CP210x Driver Memory Corruption results in Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15419"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-88004",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-436",
      "title": "Traefik entrypoint header-name sanitization bypassed via request trailers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88004"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-88008",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-444",
      "title": "Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88008"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-88924",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-367",
      "title": "Gvfs: gvfs-admin socket ownership race permits local root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88924"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-15417",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "silabser.sys driver",
      "cwe": "CWE-369",
      "title": "CP210x Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15417"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-17038",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "drEryk",
      "product": "drEryk Gabinet",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in drEryk Gabinet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17038"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-78085",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Property extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78085"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-84941",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Software Controller (Windows)",
      "cwe": "CWE-611",
      "title": "Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84941"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-88050",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-787",
      "title": "Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88050"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-88054",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tesseract-ocr",
      "product": "tesseract",
      "cwe": "CWE-125",
      "title": "Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88054"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-88878",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-770",
      "title": "Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88878"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-88884",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "renovatebot",
      "product": "renovate",
      "cwe": "CWE-863",
      "title": "Renovate before 44.3.1 Authentication Bypass via Digest Updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88884"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-88896",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espocrm",
      "product": "espocrm",
      "cwe": "CWE-918",
      "title": "EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88896"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-88940",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knowns-dev",
      "product": "knowns",
      "cwe": "CWE-22",
      "title": "knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88940"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-89044",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-444",
      "title": "Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89044"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-52097",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52097"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-81052",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-494",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81052"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-9176",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-94",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9176"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-81051",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-1328",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81051"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-9225",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9225"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-9336",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-306",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9336"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-54054",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "transmute-app",
      "product": "transmute",
      "cwe": "CWE-918",
      "title": "Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54054"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-66632",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elliot Sowers/ RelyWP",
      "product": "Simple Cloudflare Turnstile",
      "cwe": "CWE-94",
      "title": "WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Content Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66632"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-78536",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "robokassa",
      "product": "Robokassa payment gateway for Woocommerce",
      "cwe": "CWE-862",
      "title": "WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78536"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-79725",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-284",
      "title": "Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79725"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-81275",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Youzify",
      "product": "Youzify",
      "cwe": "CWE-22",
      "title": "WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81275"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-81782",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fahad Mahmood",
      "product": "WP Docs",
      "cwe": "CWE-79",
      "title": "WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81782"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-81785",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themekraft",
      "product": "BuddyForms",
      "cwe": "CWE-862",
      "title": "WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81785"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-81787",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IDX Broker",
      "product": "IMPress for IDX Broker",
      "cwe": "CWE-288",
      "title": "WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81787"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-81791",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ashan Perera",
      "product": "EventON",
      "cwe": "CWE-79",
      "title": "WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81791"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-81793",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dimitri Grassi",
      "product": "Salon booking system",
      "cwe": "CWE-862",
      "title": "WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81793"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-84828",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-732",
      "title": "Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84828"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-85310",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adrian Tobey",
      "product": "Groundhogg",
      "cwe": "CWE-35",
      "title": "WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85310"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-87106",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-400",
      "title": "Consul vulnerable to a denial of service in the native RPC listener",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87106"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-88005",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-863",
      "title": "Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88005"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-88006",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-863",
      "title": "Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88006"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-89089",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The OpenNMS Group",
      "product": "Meridian",
      "cwe": "CWE-89",
      "title": "OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89089"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-9327",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-269",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9327"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-18121",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18121"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-81788",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IDX Broker",
      "product": "IMPress for IDX Broker",
      "cwe": "CWE-862",
      "title": "WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81788"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-81905",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-863",
      "title": "Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81905"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-81906",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-288",
      "title": "[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81906"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-88014",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-22",
      "title": "rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88014"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-88859",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-84",
      "title": "Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88859"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-88023",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB PHP Library",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP Library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88023"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-88024",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Rust Driver",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88024"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-88025",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C# Driver",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88025"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-88029",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Python Driver",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88029"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-88030",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Ruby Driver",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88030"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-88031",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Go Driver",
      "cwe": "CWE-943",
      "title": "GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88031"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-88033",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Java Driver",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88033"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-88034",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C++ Driver",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88034"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-88036",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-943",
      "title": "GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88036"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-16172",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netskope",
      "product": "Endpoint DLP",
      "cwe": "CWE-125",
      "title": "Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16172"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-19596",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The OpenNMS Group",
      "product": "Meridian",
      "cwe": "CWE-611",
      "title": "OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19596"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-45751",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-416",
      "title": "Suricata detect/transform: use-after-free in dotprefix transform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45751"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-45752",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-416",
      "title": "Suricata detect/transform: use-after-free in decompress transforms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45752"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-45763",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-770",
      "title": "Suricata lua: sandbox allocation limit not enforced for new allocations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45763"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-49837",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osrg",
      "product": "gobgp",
      "cwe": "CWE-125",
      "title": "GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49837"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-49838",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osrg",
      "product": "gobgp",
      "cwe": "CWE-129",
      "title": "GoBGP confederation validation panics on empty AS_PATH attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49838"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-68527",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-639",
      "title": "Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68527"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-88061",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "santifer",
      "product": "career-ops",
      "cwe": "CWE-352",
      "title": "career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing unauthenticated command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88061"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-88035",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-190",
      "title": "Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88035"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-66674",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elliot Sowers/ RelyWP",
      "product": "Simple Cloudflare Turnstile",
      "cwe": "CWE-290",
      "title": "WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66674"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-88055",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mintplex-Labs",
      "product": "anything-llm",
      "cwe": "CWE-79",
      "title": "AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88055"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-12682",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ankaref Innovation and Technology Inc.",
      "product": "LIBRID/LIBREF",
      "cwe": "CWE-79",
      "title": "Stored XSS in Ankaref's LIBRID/LIBREF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12682"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-12683",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ankaref Innovation and Technology Inc.",
      "product": "LIBRID/LIBREF",
      "cwe": "CWE-79",
      "title": "Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12683"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-87107",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Consul",
      "cwe": "CWE-863",
      "title": "Consul vulnerable to an authorization bypass in the catalog deregistration path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87107"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-9161",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DernekPlus",
      "product": "Website Template",
      "cwe": "CWE-204",
      "title": "User Enumeration in DernekPlus' Website Template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9161"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-9338",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-400",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9338"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-9667",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-918",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9667"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-15461",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-843",
      "title": "Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15461"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-76653",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR6400 v8",
      "cwe": "CWE-126",
      "title": "Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76653"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-84432",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84432"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-88011",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-290",
      "title": "Traefik: ForwardAuth identity spoofing via dot-form header alias",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88011"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-88012",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-770",
      "title": "Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88012"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-88015",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-190",
      "title": "rclone local: crafted Range request against a translated symlink panics (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88015"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-88046",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-22",
      "title": "rclone: source object names can escape the configured root on upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88046"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-88057",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88057"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-88871",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo CustomizeUser setSubscribers CSRF via GET",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88871"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-88875",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-359",
      "title": "AVideo Incomplete API Sanitization Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88875"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-88879",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-290",
      "title": "Traefik before v2.11.56 Identity Spoofing via Header Alias",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88879"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-88892",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-918",
      "title": "OpenPanel SSRF via Unguarded Importer File URL Fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88892"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-88894",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88894"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-85544",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "DS-KV9503",
      "cwe": "CWE-1310",
      "title": "There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85544"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-87912",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Security Agent plugin",
      "cwe": "CWE-283",
      "title": "Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87912"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-87913",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Security Agent MCP server",
      "cwe": "CWE-283",
      "title": "Missing S3 bucket ownership verification in the AWS Security Agent MCP server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87913"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-88921",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP: Unescaped HTML Injection in PDF Report Element Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88921"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-89045",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "luben",
      "product": "zstd-jni",
      "cwe": "CWE-835",
      "title": "zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89045"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-79723",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79723"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-76652",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-MR6400 v8",
      "cwe": "CWE-22",
      "title": "Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76652"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-88038",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cookies",
      "product": "cookies",
      "cwe": "CWE-74",
      "title": "cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88038"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-3096",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Control Plane",
      "cwe": "CWE-20",
      "title": "Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3096"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-49836",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "psd-tools",
      "product": "psd-tools",
      "cwe": "CWE-22",
      "title": "psd-tools: arbitrary file write via smart-object filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49836"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-45767",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-22",
      "title": "Suricata datasets: save to absolute filename can be bypassed when combined with load command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45767"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-81049",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-353",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81049"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-85543",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "Wi-Fi series camera",
      "cwe": "CWE-285",
      "title": "Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85543"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-86087",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-22",
      "title": "IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86087"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-88059",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-200",
      "title": "Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88059"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-88013",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-200",
      "title": "rclone: http backend forwards custom/auth headers to a different host on redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88013"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-45761",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-122",
      "title": "Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45761"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-15418",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "silabser.sys driver",
      "cwe": "CWE-130",
      "title": "CP210x Memory Leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15418"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-88790",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "proma-ai",
      "product": "Proma",
      "cwe": "CWE-22",
      "title": "proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88790"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2022-26962",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-26962"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2025-57231",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-57231"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-36392",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client user who visits the store page, enabling session hijacking, account takeover, and phishing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36392"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-38626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38626"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-68006",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68006"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-71640",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71640"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-71642",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71642"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-71643",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71643"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-71645",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71645"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-71647",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71647"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-79590",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79590"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-79591",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79591"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-79592",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79592"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-67277",
      "detail": "ADDED TO KEV — CVE-2026-67277 (Mikrotik RouterOS). Remediation due September 13, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-86060",
      "detail": "ADDED TO KEV — CVE-2026-86060 (Mikrotik RouterOS). Remediation due September 13, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-41352",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-41352. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-22373",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-22373 (Grassroot DICOM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-25249",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-25249 (Fortinet FortiSwitchManager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62718",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62718 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-20079",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25639 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-27606",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-27606 (rollup). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-27962",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-27962 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28498",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28498 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28802",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28802 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-29074",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-29074 (svgo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-30922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32286",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32597",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32597 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42033 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42039 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42041 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42043",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42043 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42044 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42945",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44486 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44487 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44488 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44494 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45736",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4598",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4598 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4599",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4599 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4600",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4600 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4601",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4601 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4602",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4602 (jsrsasign). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56101",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56101 (OpenBSD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5704",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61517",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61517 (Netis Systems NX10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67277",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67277 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6958",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6958 (Invicti Security Corp. Acunetix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73311",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73311 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73314",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73314 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73316",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73316 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73319",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73319 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73321",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73321 (XenForo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80093",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80093 (Microsoft Windows 10 Version 1809). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80113",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80113 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80118",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80118 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82533",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82533 (DeepSeek Harness). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85639 (jofpin trape). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85704",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85704 (ramon-victor freegpt-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86060",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86060 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86208",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86208 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86213",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86213 (Mstfakts College-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86666",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86666 (aircheng-org iWebShop-5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86675",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86675 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86776",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86776 (KeePass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87441",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87441 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87445",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87445 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87447",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87447 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87475",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87475 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87482",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87482 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87483",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87483 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87484",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87484 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87486 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87496 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87497 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87501",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87501 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87503",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87503 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87505",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87505 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87513",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87513 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87515",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87515 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87528",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87528 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87532",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87532 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87533",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87533 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87535",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87535 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87540",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87540 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87577",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87577 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87586",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87586 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87596",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87596 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87599",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87599 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87615",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87615 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87922 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87924",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87924 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2015-3246",
      "detail": "DUE DATE PASSED — CVE-2015-3246. CISA remediation deadline was September 9, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2015-5287",
      "detail": "DUE DATE PASSED — CVE-2015-5287. CISA remediation deadline was September 9, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2021-23758",
      "detail": "DUE DATE PASSED — CVE-2021-23758 (AjaxPro.2). CISA remediation deadline was September 9, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2022-0995",
      "detail": "DUE DATE PASSED — CVE-2022-0995 (kernel). CISA remediation deadline was September 9, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2016-4117",
      "detail": "RESCORED — CVE-2016-4117. CVSS 7.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2020-14498",
      "detail": "RESCORED — CVE-2020-14498 (HMS Industrial Networks AB eCatcher). CVSS 9.6 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-14047",
      "detail": "RESCORED — CVE-2024-14047 (Elastic Security). CVSS 7.2 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-25249",
      "detail": "RESCORED — CVE-2025-25249 (Fortinet FortiSwitchManager). CVSS 7.4 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16481",
      "detail": "RESCORED — CVE-2026-16481 (Google MCP Toolbox for Databases (googleapis/mcp-toolbox)). CVSS 8.4 → 6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18622",
      "detail": "RESCORED — CVE-2026-18622 (Foxit Software Inc. Foxit PDF Editor). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-24301",
      "detail": "RESCORED — CVE-2026-24301 (Microsoft Copilot Web). CVSS 8.8 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47878",
      "detail": "RESCORED — CVE-2026-47878 (Spring Batch). CVSS 5.6 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47879",
      "detail": "RESCORED — CVE-2026-47879 (Spring Cloud Gateway). CVSS 7.7 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69803",
      "detail": "RESCORED — CVE-2026-69803 (Microsoft Windows 10 Version 1607). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69929",
      "detail": "RESCORED — CVE-2026-69929 (Microsoft Windows 10 Version 1607). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69930",
      "detail": "RESCORED — CVE-2026-69930 (Microsoft Windows 10 Version 1607). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70124",
      "detail": "RESCORED — CVE-2026-70124 (Microsoft Windows 10 Version 1607). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73763",
      "detail": "RESCORED — CVE-2026-73763 (Hewlett Packard Enterprise (HPE) AOS-CX). CVSS 7.1 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73778",
      "detail": "RESCORED — CVE-2026-73778 (Hewlett Packard Enterprise (HPE) AOS-CX). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75003",
      "detail": "RESCORED — CVE-2026-75003 (Roundcube Webmail). CVSS 5.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78523",
      "detail": "RESCORED — CVE-2026-78523 (Microsoft Windows 10 Version 1607). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81994",
      "detail": "RESCORED — CVE-2026-81994 (Adobe Acrobat). CVSS 8.2 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-87534",
      "detail": "RESCORED — CVE-2026-87534 (Google Chrome). CVSS 6.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-87641",
      "detail": "RESCORED — CVE-2026-87641 (Google Chrome). CVSS 5.3 → 4.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-87925",
      "detail": "RESCORED — CVE-2026-87925 (Rizwan17 inventory-management-system). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-87926",
      "detail": "RESCORED — CVE-2026-87926 (Rizwan17 inventory-management-system). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-87931",
      "detail": "RESCORED — CVE-2026-87931 (Behavioral Technology Group Pavlok Behavioral Conditioning Wearable). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-9736",
      "detail": "RESCORED — CVE-2026-9736 (IBM Netezza Software). CVSS 5.3 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-9744",
      "detail": "RESCORED — CVE-2026-9744 (IBM Netezza Software). CVSS 5.3 → 5.9 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-73392",
      "detail": "REJECTED — CVE-2026-73392 (highwarden Super Store Finder). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-19654",
      "detail": "PATCH SHIPPED — CVE-2026-19654 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:8.2412.0-1.el10_0.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-85150",
      "detail": "PATCH SHIPPED — CVE-2026-85150 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.2."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-87544",
      "detail": "ENRICHED — CVE-2026-87544 (Google Chrome). Received CVSS 9.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-87546",
      "detail": "ENRICHED — CVE-2026-87546 (Google Chrome). Received CVSS 4.3 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-87551",
      "detail": "ENRICHED — CVE-2026-87551 (Google Chrome). Received CVSS 4.3 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-87571",
      "detail": "ENRICHED — CVE-2026-87571 (Google Chrome). Received CVSS 5.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-87575",
      "detail": "ENRICHED — CVE-2026-87575 (Google Chrome). Received CVSS 5.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-87656",
      "detail": "ENRICHED — CVE-2026-87656 (Google Chrome). Received CVSS 5.4 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
