{
  "day": "2026-09-13",
  "boundary": "UTC calendar day",
  "published_count": 132,
  "by_severity": {
    "CRITICAL": 5,
    "HIGH": 27,
    "MEDIUM": 56,
    "LOW": 44
  },
  "kev_count": 0,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-81648",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CryptoPayment Gateway",
      "cwe": null,
      "title": "CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81648"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-90605",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-120",
      "title": "Totolink A3002MU boa formFilter buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90605"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-90606",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-120",
      "title": "Totolink A3002MU boa formIpv6Setup buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90606"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-90561",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strapi",
      "product": "strapi",
      "cwe": "CWE-79",
      "title": "Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90561"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-90562",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langbot-app",
      "product": "LangBot",
      "cwe": "CWE-331",
      "title": "LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90562"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-74933",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GenieWords",
      "cwe": null,
      "title": "GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74933"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-85129",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hoo Companion",
      "cwe": null,
      "title": "Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85129"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-88793",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YouTube Embed",
      "cwe": null,
      "title": "YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88793"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-90668",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UnrealIRCd",
      "product": "UnrealIRCd",
      "cwe": "CWE-770",
      "title": "The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90668"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-90770",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openspug",
      "product": "spug",
      "cwe": "CWE-78",
      "title": "Spug through 3.4.0 Remote Code Execution via ping_check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90770"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-90774",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orhun",
      "product": "rustypaste",
      "cwe": "CWE-22",
      "title": "rustypaste before 0.18.1 Path Traversal via filename header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90774"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-90776",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-407",
      "title": "Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90776"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-90777",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espnet",
      "product": "espnet",
      "cwe": "CWE-502",
      "title": "ESPnet before 202609 Remote Code Execution via Unsafe Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90777"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-90778",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SIPp",
      "product": "sipp",
      "cwe": "CWE-120",
      "title": "SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90778"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-90779",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SIPp",
      "product": "sipp",
      "cwe": "CWE-121",
      "title": "SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90779"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-90780",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SIPp",
      "product": "sipp",
      "cwe": "CWE-120",
      "title": "SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90780"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-90768",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kevoreilly",
      "product": "CAPEv2",
      "cwe": "CWE-862",
      "title": "CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90768"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-90493",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tonec",
      "product": "Internet Download Manager",
      "cwe": "CWE-266",
      "title": "Tonec Internet Download Manager Kernel Driver idmwfp.sys access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90493"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-90783",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moritz Bunkus",
      "product": "MKVToolNix",
      "cwe": "CWE-680",
      "title": "MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90783"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-90769",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lfnovo",
      "product": "open-notebook",
      "cwe": "CWE-918",
      "title": "Open Notebook before 1.11.0 Server-Side Request Forgery via link-source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90769"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-90772",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amundsen-io",
      "product": "amundsen-frontend",
      "cwe": "CWE-79",
      "title": "Amundsen Frontend through 4.3.0 Stored XSS via Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90772"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-37008",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CrewAI",
      "product": "CrewAI",
      "cwe": "CWE-424",
      "title": "CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox cannot merely account for the import system and instead must account for the complete runtime of the Python interpreter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37008"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-29811",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberPanel",
      "product": "CyberPanel",
      "cwe": "CWE-1025",
      "title": "CyberPanel before 2.4.4 attempts to detect an \"alais\" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled \"alias\") via an ORM query filter rather than a Python \"if\" statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29811"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-15891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15891"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-86406",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-269",
      "title": "User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership Purchase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86406"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-88802",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MDJM Event Management",
      "cwe": null,
      "title": "MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88802"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-89080",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Really Simple Security",
      "cwe": "CWE-287",
      "title": "Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89080"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-90678",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAProxy",
      "product": "HAProxy",
      "cwe": "CWE-130",
      "title": "An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, when an HTTP/3 request carries no Content-Length header, the HTTP/3 multiplexer credits the length declared in a DATA frame header to the stream endpoint's known-input-payload estimate at the moment the frame header is decoded, before the payload has been received, and that declared length is emitted verbatim as the HTTP/1.1 chunk size. A remote unauthenticated client that declares more payload than it delivers and then ends the stream causes HAProxy to announce a chunk larger than the bytes it writes and to return the connection to the idle pool in a desynchronized state. The result is potential HTTP request smuggling on reused backend connections: an attacker can place a request past a frontend rule such as a path-based http-request deny, so that the smuggled request is never seen by HAProxy's HTTP analysis, and can cause concurrent clients' requests, including their request lines and Authorization headers, to be consumed as the attacker's request body and lost. Exploitation is not deterministic; it depends on a race with backend connection pooling, succeeding in a majority of but not all trials during testing, and can be retried freely. The mechanism was introduced in 3.3-dev10; releases 3.2.x and earlier are unaffected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90678"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-36453",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rhymix",
      "product": "Rhymix",
      "cwe": "CWE-425",
      "title": "Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36453"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-80071",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-269",
      "title": "User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80071"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-90767",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "Froxlor",
      "cwe": "CWE-93",
      "title": "Froxlor before 2.3.12 SSH Key Injection via authorized_keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90767"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-90775",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PostGIS",
      "product": "address_standardizer",
      "cwe": "CWE-125",
      "title": "PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90775"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-90494",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "restify",
      "product": "node-restify",
      "cwe": "CWE-22",
      "title": "restify node-restify static.js serveStatic path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90494"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-90513",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simalexan",
      "product": "api-lambda-send-email-ses",
      "cwe": "CWE-287",
      "title": "simalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90513"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-90593",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "embedded-graphics",
      "cwe": "CWE-189",
      "title": "embedded-graphics image_raw.rs draw_sub_image integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90593"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-90596",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "embedded-graphics",
      "cwe": "CWE-189",
      "title": "embedded-graphics image_raw.rs new/bytes_per_row integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90596"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-90601",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getzep",
      "product": "graphiti",
      "cwe": "CWE-287",
      "title": "getzep graphiti REST API main.py improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90601"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-90603",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anil-matcha",
      "product": "Open-Generative-AI",
      "cwe": "CWE-284",
      "title": "Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90603"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2022-42917",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FRRouting",
      "product": "FRRouting",
      "cwe": "CWE-367",
      "title": "In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-42917"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-70819",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zettlab",
      "product": "D6 Ultra",
      "cwe": "CWE-24",
      "title": "Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via \"..\" manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70819"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-90771",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "joi",
      "cwe": "CWE-1321",
      "title": "joi before 17.13.8 and 18.2.9 Prototype Pollution via messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90771"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-90782",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Systerel",
      "product": "S2OPC",
      "cwe": "CWE-476",
      "title": "S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_items()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90782"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-36989",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LuxSoft",
      "product": "LuxCal Web Calendar",
      "cwe": "CWE-89",
      "title": "A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36989"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2024-53922",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 8890 firmware",
      "cwe": "CWE-1284",
      "title": "An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-53922"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-90495",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fengoffice",
      "product": "Feng Office",
      "cwe": "CWE-74",
      "title": "Fengoffice Feng Office Legacy API CompanyWebsite.class.php instance->findAll sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90495"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-90498",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lenve",
      "product": "vhr",
      "cwe": "CWE-1392",
      "title": "lenve vhr vhr.sql default credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90498"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-90504",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vvbbnn00",
      "product": "WARP-Clash-API",
      "cwe": "CWE-287",
      "title": "vvbbnn00 WARP-Clash-API authorized missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90504"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-90509",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "orion-visor",
      "cwe": "CWE-259",
      "title": "dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90509"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-90510",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "orion-visor",
      "cwe": "CWE-320",
      "title": "dromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90510"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-90514",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "School Registration and Fee System",
      "cwe": "CWE-74",
      "title": "SourceCodester School Registration and Fee System save_stud.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90514"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-90515",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "School Registration and Fee System",
      "cwe": "CWE-74",
      "title": "SourceCodester School Registration and Fee System delete_stud.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90515"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-90516",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "School Registration and Fee System",
      "cwe": "CWE-74",
      "title": "SourceCodester School Registration and Fee System pay_report.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90516"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-90517",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Bank Locker Management System",
      "cwe": "CWE-285",
      "title": "PHPGurukul Bank Locker Management System view-assign-locker.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90517"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-90522",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaychouchannel",
      "product": "Tourism-Management-System",
      "cwe": "CWE-640",
      "title": "jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90522"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-90523",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaychouchannel",
      "product": "Tourism-Management-System",
      "cwe": "CWE-266",
      "title": "jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90523"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-90524",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaychouchannel",
      "product": "Tourism-Management-System",
      "cwe": "CWE-287",
      "title": "jaychouchannel Tourism-Management-System Update Endpoint missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90524"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-90526",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "School Registration and Fee System",
      "cwe": "CWE-74",
      "title": "SourceCodester School Registration and Fee System save_class.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90526"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-90565",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rizwan17",
      "product": "inventory-management-system",
      "cwe": "CWE-266",
      "title": "Rizwan17 inventory-management-system dashboard.php access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90565"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-90566",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rizwan17",
      "product": "inventory-management-system",
      "cwe": "CWE-266",
      "title": "Rizwan17 inventory-management-system Registration register.php createUserAccount improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90566"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-90579",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cheshire-cat-ai",
      "product": "Cheshire Cat AI",
      "cwe": "CWE-287",
      "title": "cheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90579"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-90582",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "evanchiu",
      "product": "serverless-todo",
      "cwe": "CWE-400",
      "title": "evanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90582"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-90584",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TooTallNate",
      "product": "Java-WebSocket",
      "cwe": "CWE-400",
      "title": "TooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90584"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2025-63842",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repetico",
      "product": "web backend",
      "cwe": "CWE-79",
      "title": "A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63842"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-88764",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Membership",
      "cwe": "CWE-269",
      "title": "Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88764"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-15892",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-401",
      "title": "Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15892"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-77773",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Contact Form to Chat Apps | Click to Chat to Order",
      "cwe": "CWE-200",
      "title": "Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77773"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-88995",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bookit — Booking & Appointment Calendar",
      "cwe": "CWE-200",
      "title": "Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88995"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-90527",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quequnlong",
      "product": "shiyi-blog",
      "cwe": "CWE-79",
      "title": "quequnlong shiyi-blog Add Message API index.vue cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90527"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-90571",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exrick",
      "product": "xmall",
      "cwe": "CWE-79",
      "title": "Exrick xmall Order Printing order-print.jsp cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90571"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-90583",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kagisearch",
      "product": "smallweb",
      "cwe": "CWE-79",
      "title": "kagisearch smallweb Query String Rendering sw.py index cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90583"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-90528",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckApp",
      "product": "tduck-platform",
      "cwe": "CWE-79",
      "title": "TDuckApp tduck-platform Form Write View index.vue cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90528"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-90529",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DataEase",
      "cwe": "CWE-79",
      "title": "DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90529"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-90563",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maliangnansheng",
      "product": "bbs-springboot",
      "cwe": "CWE-79",
      "title": "maliangnansheng bbs-springboot ArticleController.java utils.toToc cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90563"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-90564",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quequnlong",
      "product": "shiyi-blog",
      "cwe": "CWE-79",
      "title": "quequnlong shiyi-blog chat sendMsg Endpoint index.vue SysChatMsgMapper.getChatMsgList cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90564"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-90567",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quequnlong",
      "product": "shiyi-blog",
      "cwe": "CWE-79",
      "title": "quequnlong shiyi-blog Search index.vue highlightKeyword cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90567"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-90568",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moxi624",
      "product": "Mogu Blog v2",
      "cwe": "CWE-79",
      "title": "moxi624 Mogu Blog v2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSort cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90568"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-90602",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anil-matcha",
      "product": "Open-Generative-AI",
      "cwe": "CWE-79",
      "title": "Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90602"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-90604",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-79",
      "title": "Totolink A3002MU Anchor Tag cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90604"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2020-15875",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LibreNMS",
      "product": "LibreNMS",
      "cwe": "CWE-89",
      "title": "An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php, edit-ports.inc.php, alertlog-stats.inc.php, alerts.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, and toner.inc.php (in includes/html/table). NOTE: some sources refer to this as CVE-2020-15876, but CVE-2020-15875 is the only correct CVE ID.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-15875"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-90569",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linlinjava",
      "product": "litemall",
      "cwe": "CWE-79",
      "title": "linlinjava litemall Admin Topic index.vue AdminTopicController.validate cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90569"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-90570",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linlinjava",
      "product": "litemall",
      "cwe": "CWE-79",
      "title": "linlinjava litemall Product Detail index.vue AdminGoodsService.validate cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90570"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-90781",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ALSA Project",
      "product": "alsa-lib",
      "cwe": "CWE-193",
      "title": "alsa-lib through 1.2.16.1 Off-by-One Stack Buffer Overflow in __snd_ctl_ascii_elem_id_parse()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90781"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-80072",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-601",
      "title": "User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80072"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-29810",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberPanel",
      "product": "CyberPanel",
      "cwe": "CWE-390",
      "title": "CyberPanel before 2.4.4 omits a \"return 0\" that is required by the business logic.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29810"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-29812",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberPanel",
      "product": "CyberPanel",
      "cwe": "CWE-778",
      "title": "CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29812"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-89050",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quads Ads Manager for Google AdSense",
      "cwe": null,
      "title": "Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89050"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-90679",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forgejo",
      "product": "Forgejo",
      "cwe": "CWE-348",
      "title": "Forgejo 13.0.0 through 16.0.4, when \"[federation] ENABLED = true\" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming ActivityPub activity was produced by the key belonging to the actor named in the activity body. The signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, but the inbox activity handlers subsequently read the acting identity from the attacker-controlled JSON body without binding it to the verified signing key. Additionally, the signed Digest header is not recomputed against the received request body. A remote attacker who hosts a single valid ActivityPub actor and keypair can therefore submit signature-valid activities attributed to any actor identity they name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90679"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-88912",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "rtMedia for WordPress, BuddyPress and bbPress",
      "cwe": "CWE-639",
      "title": "rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Privacy Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88912"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-86407",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-200",
      "title": "User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membership Thank You Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86407"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2025-70820",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zettlab",
      "product": "D6 Ultra",
      "cwe": "CWE-36",
      "title": "Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70820"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-35867",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LB-LINK",
      "product": "AC1900 firmware",
      "cwe": "CWE-78",
      "title": "A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a \"POST /goform/set_LimitClient_cfg\" call but does not already have administrative access to the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35867"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2025-45480",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectfloodlight",
      "product": "Floodlight",
      "cwe": "CWE-669",
      "title": "Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-45480"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-38332",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cdcseacave",
      "product": "TinyEXIF",
      "cwe": "CWE-125",
      "title": "TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38332"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-52296",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-125",
      "title": "FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52296"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-52297",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-125",
      "title": "FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52297"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-90575",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Small CRM",
      "cwe": "CWE-20",
      "title": "PHPGurukul Small CRM Login Success login.php unserialize deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90575"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-90773",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dalance",
      "product": "procs",
      "cwe": "CWE-150",
      "title": "procs through 0.14.12 Terminal Escape Sequence Injection via Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90773"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-90490",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lenve",
      "product": "vhr",
      "cwe": "CWE-20",
      "title": "lenve vhr MailReceiver deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90490"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-90491",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sanjevirau",
      "product": "gsubs",
      "cwe": "CWE-74",
      "title": "sanjevirau gsubs Electron index.js showQuerySuccessPage code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90491"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-90492",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webgjc",
      "product": "web_robot",
      "cwe": "CWE-77",
      "title": "webgjc web_robot web.py controller_recover os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90492"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-90499",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lenve",
      "product": "vhr",
      "cwe": "CWE-266",
      "title": "lenve vhr Password Update pass HrInfoController.updatePass improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90499"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-90500",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lenve",
      "product": "vhr",
      "cwe": "CWE-284",
      "title": "lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90500"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-90501",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lenve",
      "product": "vhr",
      "cwe": "CWE-266",
      "title": "lenve vhr HrMapper.xml HrInfoController.updateHr privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90501"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-90507",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vvbbnn00",
      "product": "WARP-Clash-API",
      "cwe": "CWE-266",
      "title": "vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90507"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-90511",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GongShengyue",
      "product": "OnlineBooks",
      "cwe": "CWE-74",
      "title": "GongShengyue OnlineBooks listSplit BooksServlet.java sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90511"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-90518",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Bank Locker Management System",
      "cwe": "CWE-266",
      "title": "PHPGurukul Bank Locker Management System sidebar.php access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90518"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-90519",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Bank Locker Management System",
      "cwe": "CWE-284",
      "title": "PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90519"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-90520",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaychouchannel",
      "product": "Tourism-Management-System",
      "cwe": "CWE-266",
      "title": "jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90520"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-90521",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaychouchannel",
      "product": "Tourism-Management-System",
      "cwe": "CWE-285",
      "title": "jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90521"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-90525",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System cust_pos_trans.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90525"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-90574",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System emp_transac.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90574"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-90580",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-918",
      "title": "FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90580"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-90581",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cym1102",
      "product": "nginxWebUI",
      "cwe": "CWE-74",
      "title": "cym1102 nginxWebUI autoUpdate MainController.autoUpdate code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90581"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-90594",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wxiaoqi",
      "product": "Spring-Cloud-Platform",
      "cwe": "CWE-862",
      "title": "wxiaoqi Spring-Cloud-Platform Permission Service PermissionService.java PermissionService.checkUserPermission authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90594"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-90595",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wxiaoqi",
      "product": "Spring-Cloud-Platform",
      "cwe": "CWE-862",
      "title": "wxiaoqi Spring-Cloud-Platform OnlineController.java OnlineController.getOnlineInfo authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90595"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-90597",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System sup_edit1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90597"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-90598",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jaygajera17",
      "product": "E-commerce-project-springBoot",
      "cwe": "CWE-285",
      "title": "jaygajera17 E-commerce-project-springBoot UserController.java UserController.updateUser authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90598"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-90599",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rizwan17",
      "product": "inventory-management-system",
      "cwe": "CWE-352",
      "title": "Rizwan17 inventory-management-system process.php cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90599"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-90600",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System inv_edit1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90600"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-90496",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fengoffice",
      "product": "Feng Office",
      "cwe": "CWE-74",
      "title": "Fengoffice Feng Office Reorder Handlers MoreController.class.php update_dimension_order sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90496"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-90497",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fengoffice",
      "product": "Feng Office",
      "cwe": "CWE-79",
      "title": "Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90497"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-90502",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stilleshan",
      "product": "ServerStatus",
      "cwe": "CWE-79",
      "title": "stilleshan ServerStatus Stats Generation main.cpp cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90502"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-90572",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davenardella",
      "product": "snap7",
      "cwe": "CWE-119",
      "title": "davenardella snap7 s7_micro_client.cpp opUpload memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90572"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-90573",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-404",
      "title": "GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90573"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-90576",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-404",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90576"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-90577",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90577"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-90578",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box list.c gf_list_count use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90578"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2025-64059",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "Grav",
      "cwe": "CWE-79",
      "title": "Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64059"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-90503",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chengdu Qilu Technology",
      "product": "Ludashi",
      "cwe": "CWE-200",
      "title": "Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90503"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-90508",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chengdu Qilu Technology",
      "product": "Ludashi",
      "cwe": "CWE-862",
      "title": "Chengdu Qilu Technology Ludashi Message Dispatch ProtectFilter64.sys MessageNotifyCallback authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90508"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-90505",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vvbbnn00",
      "product": "WARP-Clash-API",
      "cwe": "CWE-362",
      "title": "vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90505"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-90506",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vvbbnn00",
      "product": "WARP-Clash-API",
      "cwe": "CWE-362",
      "title": "vvbbnn00 WARP-Clash-API Save Account Job race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90506"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81578 (PaperCut MF/NG). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82078",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82078 (PaperCut MF/NG). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-25249",
      "detail": "DUE DATE PASSED — CVE-2025-25249 (Fortinet FortiSwitchManager). CISA remediation deadline was September 12, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-19490",
      "detail": "DUE DATE PASSED — CVE-2026-19490 (NetScaler ADC). CISA remediation deadline was September 12, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-20079",
      "detail": "DUE DATE PASSED — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). CISA remediation deadline was September 12, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-25252",
      "detail": "RESCORED — CVE-2025-25252 (Fortinet FortiOS). CVSS 4.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-52295",
      "detail": "RESCORED — CVE-2026-52295 (FFmpeg). CVSS 6.2 → 2.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-90488",
      "detail": "RESCORED — CVE-2026-90488 (Xuxueli xxl-job). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-90489",
      "detail": "RESCORED — CVE-2026-90489 (Xuxueli xxl-job). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2025-69130",
      "detail": "PATCH SHIPPED — CVE-2025-69130 (Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme). Fixed in Entrepreneur - Booking for Small Businesses WordPress Theme 3.1.5."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18369",
      "detail": "PATCH SHIPPED — CVE-2026-18369 (Red Hat Certificate System 10.4 EUS for RHEL-8). Fixed in Red Hat Certificate System 10.4 EUS for RHEL-8 8060020260814202723.07fb4edf."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
