{
  "day": "2026-09-12",
  "boundary": "UTC calendar day",
  "published_count": 94,
  "by_severity": {
    "CRITICAL": 13,
    "HIGH": 26,
    "MEDIUM": 51,
    "LOW": 4
  },
  "kev_count": 1,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-85706",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01148,
      "epss_percentile": 0.64977,
      "kev": true,
      "kev_due_at": "2026-09-14",
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-22",
      "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85706"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-78006",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00778,
      "epss_percentile": 0.53841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "The Events Calendar",
      "cwe": "CWE-502",
      "title": "The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78006"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-78159",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00762,
      "epss_percentile": 0.53333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "The Events Calendar",
      "cwe": "CWE-94",
      "title": "The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78159"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-85200",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00762,
      "epss_percentile": 0.53325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninjew",
      "product": "GEO my WP",
      "cwe": "CWE-98",
      "title": "GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85200"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-87719",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00612,
      "epss_percentile": 0.47436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-502",
      "title": "Deserialization of Untrusted Data in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87719"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-78175",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00586,
      "epss_percentile": 0.46213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-502",
      "title": "Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78175"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-16482",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtcamp",
      "product": "rtMedia for WordPress, BuddyPress and bbPress",
      "cwe": "CWE-89",
      "title": "rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection via 'compare' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16482"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-17585",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wproyal",
      "product": "Royal Addons for Elementor – Addons and Templates Kit for Elementor",
      "cwe": "CWE-200",
      "title": "Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17585"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-85198",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO",
      "cwe": "CWE-89",
      "title": "MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85198"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-77161",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "egoi",
      "product": "Smart Marketing SMS and Newsletters Forms",
      "cwe": "CWE-89",
      "title": "Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Authenticated (Subscriber+) SQL Injection via Parameter Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77161"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-11355",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "designthemes",
      "product": "DT LMS – elearning,  WordPress LMS Plugin",
      "cwe": "CWE-862",
      "title": "DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11355"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-90467",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cole",
      "product": "aiosmtplib",
      "cwe": "CWE-88",
      "title": "aiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90467"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-89172",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microchip",
      "product": "AN1044",
      "cwe": "CWE-1300",
      "title": "Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89172"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-81402",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00197,
      "epss_percentile": 0.09584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "DS Ad Rotator",
      "cwe": "CWE-434",
      "title": "DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81402"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-89267",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jowilf",
      "product": "starlette-admin",
      "cwe": "CWE-863",
      "title": "starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89267"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-80491",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SAMO Forms",
      "cwe": "CWE-89",
      "title": "SAMO Forms <= 1.0.0 - Unauthenticated SQLi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80491"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-75800",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00187,
      "epss_percentile": 0.08433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontegg SAML SSO",
      "cwe": "CWE-287",
      "title": "Frontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75800"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-84047",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Album Cover Finder",
      "cwe": "CWE-89",
      "title": "Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84047"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-87842",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Zonify",
      "cwe": "CWE-200",
      "title": "Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87842"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-81742",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BE REST Endpoints",
      "cwe": "CWE-79",
      "title": "BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81742"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-89268",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "QloApps",
      "cwe": "CWE-79",
      "title": "QloApps through 1.7.0 Reflected XSS via List Filter Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89268"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-82845",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00167,
      "epss_percentile": 0.06224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": "CWE-502",
      "title": "Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82845"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-84171",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00162,
      "epss_percentile": 0.05674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP images upload on piclect",
      "cwe": "CWE-434",
      "title": "WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84171"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-84099",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wpstorecart",
      "cwe": "CWE-502",
      "title": "IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84099"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-80494",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Yogeta WP Cloud",
      "cwe": "CWE-552",
      "title": "Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80494"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-86790",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.0472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Highlight Box",
      "cwe": "CWE-79",
      "title": "WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86790"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-87888",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YayPricing",
      "cwe": "CWE-79",
      "title": "YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87888"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-82847",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": "CWE-79",
      "title": "Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82847"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-83532",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Custom Menu Wizard Widget",
      "cwe": "CWE-79",
      "title": "Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83532"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-77005",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00149,
      "epss_percentile": 0.04449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CODE MONKEYS PROPOSALS",
      "cwe": "CWE-73",
      "title": "Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77005"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-78152",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SureRank SEO",
      "cwe": "CWE-200",
      "title": "SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78152"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-77689",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-284",
      "title": "Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77689"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-87892",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rox Appointment Booking",
      "cwe": "CWE-284",
      "title": "Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87892"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-87916",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPBot",
      "cwe": "CWE-200",
      "title": "WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87916"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-81090",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.03894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Gpx2Graphics",
      "cwe": "CWE-352",
      "title": "Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81090"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-77705",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.0379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-639",
      "title": "Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77705"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-77752",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.0379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Temporary Login Without Password",
      "cwe": "CWE-269",
      "title": "Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77752"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-77753",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Temporary Login Without Password",
      "cwe": "CWE-284",
      "title": "Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77753"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-85681",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Component",
      "cwe": "CWE-269",
      "title": "WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85681"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-87891",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rox Appointment Booking",
      "cwe": "CWE-284",
      "title": "Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87891"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-87894",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rox Appointment Booking",
      "cwe": "CWE-639",
      "title": "Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87894"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-87918",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPBot",
      "cwe": "CWE-284",
      "title": "WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87918"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-87759",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Add User Autocomplete",
      "cwe": "CWE-269",
      "title": "Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87759"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-87919",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product XML Feed Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87919"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-87797",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Sprout Invoices",
      "cwe": "CWE-862",
      "title": "Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87797"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-82851",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": "CWE-639",
      "title": "Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82851"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-84025",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BEAR",
      "cwe": "CWE-639",
      "title": "BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84025"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-77006",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00115,
      "epss_percentile": 0.0177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WebTotem Backups",
      "cwe": "CWE-73",
      "title": "WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77006"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-81429",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Export & Import WPBakery Page Builder",
      "cwe": "CWE-79",
      "title": "Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81429"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-84023",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BEAR",
      "cwe": "CWE-352",
      "title": "BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84023"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-84024",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BEAR",
      "cwe": "CWE-352",
      "title": "BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84024"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-90558",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "irontec",
      "product": "sngrep",
      "cwe": "CWE-121",
      "title": "sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90558"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-90647",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kalkitech",
      "product": "ASE2000 V2 Communication Test Set",
      "cwe": "CWE-295",
      "title": "ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90647"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-15451",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MemberPress",
      "product": "MemberPress Corporate Accounts",
      "cwe": "CWE-269",
      "title": "MemberPress Corporate Accounts <= 1.5.39 - Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15451"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-90537",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "WWBN AVideo Scheduler sendEmail Missing Authorization via Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90537"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-90560",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "luben",
      "product": "zstd-jni",
      "cwe": "CWE-125",
      "title": "zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90560"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-90559",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xerial",
      "product": "snappy-java",
      "cwe": "CWE-787",
      "title": "snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90559"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-90553",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-94",
      "title": "vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90553"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-90556",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freeciv",
      "product": "freeciv",
      "cwe": "CWE-122",
      "title": "Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90556"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-90651",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Socket",
      "product": "Socket Firewall",
      "cwe": "CWE-295",
      "title": "Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts any certificate, including self-signed and otherwise untrusted certificates, without validating the chain. An attacker positioned to intercept traffic between Socket Firewall and the Socket API or an upstream package registry can present a crafted certificate and modify responses in transit, including substituting malicious package content or altering the allow/block decisions the firewall enforces. Setting api_ssl_verify: true and upstream_ssl_verify: true enables verification; however, in versions before 1.1.334, the generated nginx configuration did not emit lua_ssl_trusted_certificate, and thus verification could not be used successfully without manually patching the generated configuration. Version 2.0.0 changes the default for both settings to true.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90651"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-90474",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "mcphub",
      "cwe": "CWE-287",
      "title": "MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90474"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-90616",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flatpak",
      "product": "Flatpak",
      "cwe": "CWE-61",
      "title": "In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90616"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-90555",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-409",
      "title": "vLLM before 0.28.0 Denial of Service via Audio Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90555"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-90648",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebAssembly",
      "product": "wabt",
      "cwe": "CWE-252",
      "title": "wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a \"table flip\" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus, bounds checks still pass and table element accesses resolve to absolute memory addresses (i * sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of host process memory and - via table.get, table.set, and call_indirect - arbitrary code execution, defeating the isolation that wasm2c exists to provide (a full sandbox escape). wasm2c is used as an in-process sandboxing boundary by RLBox and WasmBoxC, including in Firefox, which compiles the Graphite, Hunspell, Ogg, Expat, and Woff2 libraries via wasm2c to contain untrusted font, media, and XML input. Therefore, sandboxing in these applications is potentially affected. Exploitation requires the funcref table allocation to fail, for example under an address-space limit (RLIMIT_AS), on 32-bit hosts, with vm.overcommit_memory=2, or under memory pressure. On 64-bit Linux with default overcommit the allocation succeeds and the defect is not triggered. The wasm2c memory allocator aborts on calloc failure in the same runtime; the table allocator lacks this abort behavior. This was introduced in commit ab9e0b55 (PR #813).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90648"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-90472",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "msgpack",
      "product": "msgpack-java",
      "cwe": "CWE-674",
      "title": "msgpack-java through 0.9.12 Stack Overflow via Nested Arrays",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90472"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-90473",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "msgpack",
      "product": "msgpack-java",
      "cwe": "CWE-190",
      "title": "msgpack-java through 0.9.12 Integer Overflow via MAP32",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90473"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-90536",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Missing Authorization via adsInfo API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90536"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-90538",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Missing Authorization via playlistsFromUser.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90538"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-90539",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Missing Authentication via menuItems.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90539"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-90541",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Unauthenticated Information Disclosure via menus.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90541"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-90543",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-306",
      "title": "WWBN AVideo Missing Authentication via socketMessageLiveOwner.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90543"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-90547",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "WWBN AVideo Missing Authorization via getBookmarks.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90547"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-90548",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Missing Authorization in ImageGallery list.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90548"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-90549",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Missing Authorization via videosAndroid.json.php Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90549"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-90550",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-200",
      "title": "WWBN AVideo Missing Authorization via mediaSession.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90550"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-90551",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "WWBN AVideo Missing Authorization via video_from_program API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90551"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-90554",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-400",
      "title": "vLLM before 0.28.0 Denial of Service via audio extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90554"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-90557",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freeciv",
      "product": "freeciv",
      "cwe": "CWE-125",
      "title": "Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90557"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-10148",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "melograno",
      "product": "Booking for Appointments and Events Calendar – Amelia",
      "cwe": "CWE-79",
      "title": "Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10148"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-90535",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-862",
      "title": "Flowise before 3.1.4 Denial of Service via text-to-speech/abort",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90535"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-90534",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-639",
      "title": "Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90534"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-90533",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-862",
      "title": "Flowise before 3.1.4 Broken Access Control via organizationuser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90533"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-90485",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IOBit",
      "product": "Uninstaller",
      "cwe": "CWE-404",
      "title": "IOBit Uninstaller IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90485"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-90486",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openstatusHQ",
      "product": "openstatus",
      "cwe": "CWE-918",
      "title": "openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90486"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-90488",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xuxueli",
      "product": "xxl-job",
      "cwe": "CWE-94",
      "title": "Xuxueli xxl-job GlueFactory.java GroovyClassLoader.parseClass code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90488"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-90540",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "WWBN AVideo Missing Authorization via playListAddVideo.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90540"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-90542",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "WWBN AVideo Missing Authorization via remindMe.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90542"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-90544",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "WWBN AVideo Missing Authorization via videoAddViewCount.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90544"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-90545",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "WWBN AVideo Missing Authorization via commentAddNew.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90545"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-90546",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "WWBN AVideo Missing Authorization via like.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90546"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-90552",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "WWBN AVideo Missing Authorization via Playlists_schedules list.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90552"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-90489",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xuxueli",
      "product": "xxl-job",
      "cwe": "CWE-79",
      "title": "Xuxueli xxl-job insert cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90489"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-79300",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEP",
      "product": "sesam",
      "cwe": "CWE-180",
      "title": "SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for the same Active Directory (AD) account. Active Directory treats usernames as case-insensitive, while SEP sesam distinguishes between different letter casing. As a result, the same AD user can be represented by multiple SEP sesam user accounts that differ only in username capitalization. When Active Directory authentication is configured and multi-factor authentication (MFA) is enforced, this behavior may allow an additional OTP Authenticator to be registered for the same AD account, reducing the effectiveness of MFA protection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79300"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-90487",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xuxueli",
      "product": "xxl-job",
      "cwe": "CWE-266",
      "title": "Xuxueli xxl-job JobGroupController.java privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90487"
    }
  ],
  "transactions": [
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-75650",
      "detail": "DUE DATE PASSED — CVE-2026-75650 (Adobe Commerce). CISA remediation deadline was September 11, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-86218",
      "detail": "DUE DATE PASSED — CVE-2026-86218 (N-able N-central). CISA remediation deadline was September 11, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
