{
  "day": "2026-09-14",
  "boundary": "UTC calendar day",
  "published_count": 777,
  "by_severity": {
    "CRITICAL": 54,
    "HIGH": 181,
    "MEDIUM": 218,
    "LOW": 97
  },
  "kev_count": 1,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 227,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-76461",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-09-17",
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-89",
      "title": "Cisco Secure Email Gateway SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76461"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-90617",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.016,
      "epss_percentile": 0.74419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GH05TCREW",
      "product": "PentestAgent",
      "cwe": "CWE-77",
      "title": "GH05TCREW PentestAgent MCP HTTP Server main.py run_task os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90617"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-90618",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.016,
      "epss_percentile": 0.74419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GH05TCREW",
      "product": "PentestAgent",
      "cwe": "CWE-77",
      "title": "GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90618"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-90699",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01593,
      "epss_percentile": 0.74312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M920",
      "cwe": "CWE-77",
      "title": "D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90699"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-90619",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01362,
      "epss_percentile": 0.70204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0x4m4",
      "product": "HexStrike AI",
      "cwe": "CWE-77",
      "title": "0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90619"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-90690",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0135,
      "epss_percentile": 0.69919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0x4m4",
      "product": "HexStrike AI",
      "cwe": "CWE-77",
      "title": "0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90690"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-82762",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01186,
      "epss_percentile": 0.66079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "FXA5000",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82762"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-82766",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01186,
      "epss_percentile": 0.66078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "SGA1000",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82766"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-82774",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01186,
      "epss_percentile": 0.66079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "M2M Gateway Integrated Type CPS-MG341*",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82774"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-82777",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01186,
      "epss_percentile": 0.66079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Integrated Type CPS-PC341[][]-*-9201",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82777"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-90621",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01088,
      "epss_percentile": 0.63442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ipa-lab",
      "product": "HackingBuddyGPT",
      "cwe": "CWE-77",
      "title": "ipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90621"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-82779",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01023,
      "epss_percentile": 0.61567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd",
      "product": "CPS-TM341G5MB-ADSC1-931",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82779"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-82791",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01023,
      "epss_percentile": 0.61568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "CAN-2-WF",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82791"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-82794",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01023,
      "epss_percentile": 0.61568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "SV-CPT-MC310",
      "cwe": "CWE-78",
      "title": "SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82794"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2023-40772",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01008,
      "epss_percentile": 0.61108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataEase",
      "product": "DataEase",
      "cwe": "CWE-23",
      "title": "A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-40772"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-90608",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00796,
      "epss_percentile": 0.54429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-119",
      "title": "Totolink A3002MU boa formPortFw buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90608"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2023-24035",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00767,
      "epss_percentile": 0.53533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios",
      "product": "Nagios XI",
      "cwe": "CWE-208",
      "title": "An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24035"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2023-45858",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00659,
      "epss_percentile": 0.49583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paessler",
      "product": "PRTG Network Monitor",
      "cwe": "CWE-23",
      "title": "A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-45858"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-90689",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.46932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E formDelWebAuthWhiteUser stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90689"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-90680",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00511,
      "epss_percentile": 0.42031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-823G",
      "cwe": "CWE-119",
      "title": "D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90680"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-90686",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00496,
      "epss_percentile": 0.41119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box loader_bt.c gf_bt_report memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90686"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-90698",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00496,
      "epss_percentile": 0.4112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "memcached",
      "cwe": "CWE-119",
      "title": "memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90698"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-85192",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00485,
      "epss_percentile": 0.40317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Conditional Content Pro extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85192"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2023-29377",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00485,
      "epss_percentile": 0.40358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softing",
      "product": "Secure Integration Server",
      "cwe": "CWE-23",
      "title": "An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-29377"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-90692",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-878",
      "cwe": "CWE-119",
      "title": "D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90692"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-90693",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-878",
      "cwe": "CWE-119",
      "title": "D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90693"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-90607",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.39073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-119",
      "title": "Totolink A3002MU boa formNewSchedule buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90607"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-82770",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "RP-WAH-SR1",
      "cwe": "CWE-120",
      "title": "Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82770"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-82772",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "ECE1000",
      "cwe": "CWE-120",
      "title": "Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82772"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-71198",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Glance",
      "cwe": "CWE-918",
      "title": "In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An authenticated user can add a location pointing to internal endpoints such as the cloud metadata service (169.254.169.254), and retrieve the response by downloading the image data. This affects both the new POST /v2/images/{id}/locations API and the old PATCH API when show_multiple_locations is enabled. Deployments with the HTTP store backend enabled are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71198"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-90691",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.3622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0x4m4",
      "product": "HexStrike AI",
      "cwe": "CWE-22",
      "title": "0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90691"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-90688",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E HTTP formIPMacBindAdd stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90688"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-90620",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0x4m4",
      "product": "HexStrike AI",
      "cwe": "CWE-287",
      "title": "0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90620"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2023-24034",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00385,
      "epss_percentile": 0.31954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nagios",
      "product": "Nagios XI",
      "cwe": "CWE-601",
      "title": "An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24034"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2023-46035",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00363,
      "epss_percentile": 0.29746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fnando",
      "product": "svg_optimizer",
      "cwe": "CWE-776",
      "title": "The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-46035"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-82787",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "CPSL-08P1EN",
      "cwe": "CWE-306",
      "title": "Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82787"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-82768",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "SGA1000",
      "cwe": "CWE-23",
      "title": "Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82768"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-82793",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "CAN-2-WF",
      "cwe": "CWE-434",
      "title": "Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82793"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-82780",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd",
      "product": "CPS-TM341G5MB-ADSC1-931",
      "cwe": "CWE-434",
      "title": "Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82780"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-26790",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00332,
      "epss_percentile": 0.26252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WithSecure",
      "product": "Atlant",
      "cwe": "CWE-125",
      "title": "Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-26790"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2023-50461",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "direct_mail",
      "cwe": "CWE-863",
      "title": "An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-50461"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-82765",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "FXA5000",
      "cwe": "CWE-23",
      "title": "Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82765"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-82775",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "M2M Gateway Integrated Type CPS-MG341*",
      "cwe": "CWE-548",
      "title": "An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82775"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-88932",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multer",
      "product": "multer",
      "cwe": "CWE-400",
      "title": "multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88932"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2023-46273",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "extremenetworks",
      "product": "IQ Engine",
      "cwe": "CWE-121",
      "title": "Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-46273"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-82789",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec",
      "product": "CONPROSYS HMI System(CHS)",
      "cwe": "CWE-95",
      "title": "An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82789"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-82785",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82785"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-90687",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00293,
      "epss_percentile": 0.21737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90687"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-90615",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System subject1.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90615"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82782",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.18962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82782"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2023-50462",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "content_consent",
      "cwe": "CWE-863",
      "title": "An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading to an insecure direct object reference (IDOR) issue with the potential to expose internal content elements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-50462"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-89321",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse OpenVSX",
      "cwe": "CWE-409",
      "title": "Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}/{path}, WebResourceService opened the entry with ZipFile.getInputStream() and passed the decompressed stream to Files.copy(), which ran to the end of the stream without counting bytes written. The result was cached under java.io.tmpdir, and that cache evicted by entry count (150), not by size, so it placed no bound on disk usage. A publisher with access only to their own namespace could therefore upload a small, highly compressible VSIX and cause the server to write far larger files to the temp filesystem — repeating with different files or versions, since a repeat request is served from the cache. Impact observed: the temp filesystem filled; requests for files not already cached returned 500 with No space left on device; a failed extraction left a partial cache file that blocked later attempts at that path; publishing failed with Failed to read extension file. Metadata and already-cached files kept working, and the server did not stop. Triggering the extraction needs no authentication — only the upload does.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89321"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-90623",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00264,
      "epss_percentile": 0.18343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andreashappe",
      "product": "cochise",
      "cwe": "CWE-287",
      "title": "andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90623"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-82778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Integrated Type CPS-PC341[][]-*-9201",
      "cwe": "CWE-548",
      "title": "An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82778"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-85196",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Articles Anywhere (Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85196"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-85189",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Modals (Free, Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85189"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-85190",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Quick Index (Free, Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85190"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-85191",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.15999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Tabs & Accordions (Free, Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85191"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-85195",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Articles Anywhere (Free, Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85195"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-88852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Snippets (Free) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88852"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-88853",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.15999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Modals (Pro) extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88853"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-90614",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FedML-AI",
      "product": "FedML",
      "cwe": "CWE-20",
      "title": "FedML-AI FedML MQTT+S3 Communication Backend remote_storage.py S3Storage.read_model deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90614"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2023-50459",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "femanager",
      "cwe": "CWE-863",
      "title": "An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-50459"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2023-50460",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "femanager",
      "cwe": "CWE-863",
      "title": "An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-50460"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-90697",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00238,
      "epss_percentile": 0.14918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory Management System",
      "cwe": "CWE-285",
      "title": "SourceCodester Inventory Management System invoice.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90697"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2023-34854",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digitaldruid",
      "product": "HotelDruid",
      "cwe": "CWE-434",
      "title": "HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-34854"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2023-22631",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00225,
      "epss_percentile": 0.13164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paessler",
      "product": "PRTG Network Monitor",
      "cwe": "CWE-88",
      "title": "PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-22631"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2023-22632",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00225,
      "epss_percentile": 0.13163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paessler",
      "product": "PRTG Network Monitor",
      "cwe": "CWE-88",
      "title": "PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-22632"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2023-32778",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.12904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ILIAS",
      "product": "ILIAS",
      "cwe": "CWE-23",
      "title": "An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-32778"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-85188",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Advanced Module Manager (Free, Pro) extension for Joomla",
      "cwe": "CWE-200",
      "title": "Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85188"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-25832",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TrustedFirmware",
      "product": "Mbed TLS",
      "cwe": "CWE-669",
      "title": "In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25832"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2023-28148",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paessler",
      "product": "PRTG Network Monitor",
      "cwe": "CWE-79",
      "title": "A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-28148"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-82784",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
      "cwe": "CWE-306",
      "title": "Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82784"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-90700",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System pro_edit1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90700"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-90694",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.09794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Inventory Management System Customer Management customers_handler.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90694"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-90695",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.09794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Inventory Management System Vendor Management vendors_handler.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90695"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-90696",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.09794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Inventory Management System Product Management products_handler.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90696"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-23793",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1330 firmware",
      "cwe": "CWE-787",
      "title": "An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23793"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-33970",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 850 firmware",
      "cwe": "CWE-476",
      "title": "An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33970"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2023-37252",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.09576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaWiki",
      "product": "CheckUser",
      "cwe": "CWE-669",
      "title": "An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-37252"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2023-37253",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.09576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaWiki",
      "product": "ProofreadPage",
      "cwe": "CWE-669",
      "title": "An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-37253"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-85125",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YAMAP INC.",
      "product": "YAMAP -Social Trekking GPS App",
      "cwe": "CWE-940",
      "title": "The Android application \"YAMAP -Social Trekking GPS App\" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85125"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-82786",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
      "cwe": "CWE-522",
      "title": "Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82786"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2023-51769",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe",
      "cwe": "CWE-79",
      "title": "Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-51769"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-82773",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "M2M Gateway Integrated Type CPS-MG341*",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82773"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-82776",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Integrated Type CPS-PC341[][]-*-9201",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82776"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2023-32803",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "ca-certificates",
      "cwe": "CWE-669",
      "title": "The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-32803"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-68955",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rakuten Kobo Inc.",
      "product": "The installer for Rakuten Kobo Desktop Application (Windows version)",
      "cwe": "CWE-427",
      "title": "The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68955"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2024-23176",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaWiki",
      "product": "MassMessage",
      "cwe": "CWE-79",
      "title": "An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23176"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-82769",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "RP-WAH-SR1",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82769"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-82771",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "ECE1000",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82771"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-82767",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "SGA1000",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82767"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-90622",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00161,
      "epss_percentile": 0.05583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "libredwg",
      "cwe": "CWE-404",
      "title": "GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90622"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-82788",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.0493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "CPSL-08P1EN",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82788"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-31278",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supremainc",
      "product": "BioStar 2",
      "cwe": "CWE-319",
      "title": "An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31278"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-82792",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "CAN-2-WF",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82792"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-82764",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "FXA5000",
      "cwe": "CWE-352",
      "title": "Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82764"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-82781",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82781"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-82795",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "SV-CPT-MC310",
      "cwe": "CWE-79",
      "title": "SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82795"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-82796",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "SV-CPT-MC310",
      "cwe": "CWE-79",
      "title": "SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82796"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-82763",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "FXA5000",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82763"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-82790",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "PC-HELPER Wireless I/O DIO-0404RY-LWF",
      "cwe": "CWE-79",
      "title": "Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82790"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2023-45023",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "femanager",
      "cwe": "CWE-863",
      "title": "The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-45023"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-23792",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.0313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1080 firmware",
      "cwe": "CWE-346",
      "title": "An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23792"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-82783",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contec Co., Ltd.",
      "product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
      "cwe": "CWE-256",
      "title": "Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82783"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-90682",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Matthias-Wandel",
      "product": "jhead",
      "cwe": "CWE-119",
      "title": "Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90682"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2025-64031",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00123,
      "epss_percentile": 0.02376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libarchive",
      "product": "libarchive",
      "cwe": "CWE-122",
      "title": "libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64031"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2023-24284",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simon Tatham",
      "product": "Portable Puzzle Collection",
      "cwe": "CWE-120",
      "title": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24284"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2023-24285",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simon Tatham",
      "product": "Portable Puzzle Collection",
      "cwe": "CWE-120",
      "title": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24285"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2023-24287",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simon Tatham",
      "product": "Portable Puzzle Collection",
      "cwe": "CWE-120",
      "title": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the \"M\" command.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24287"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2023-24291",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simon Tatham",
      "product": "Portable Puzzle Collection",
      "cwe": "CWE-120",
      "title": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24291"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-90611",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.01978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-617",
      "title": "GPAC MP4Box loader_xmt.c xmt_parse_element assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90611"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-90609",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.01919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-404",
      "title": "GPAC MP4Box vrml_tools.c null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90609"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-90610",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.01919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90610"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-90612",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.0192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-617",
      "title": "GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90612"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-90613",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.0192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-617",
      "title": "GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90613"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-90683",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.01919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-617",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_unregister assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90683"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2023-24283",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simon Tatham",
      "product": "Portable Puzzle Collection",
      "cwe": "CWE-120",
      "title": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24283"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-90681",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Matthias-Wandel",
      "product": "jhead",
      "cwe": "CWE-119",
      "title": "Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90681"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-90684",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00111,
      "epss_percentile": 0.01459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-617",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90684"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-90685",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00111,
      "epss_percentile": 0.0146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-617",
      "title": "GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90685"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2023-24288",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0011,
      "epss_percentile": 0.01402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simon Tatham",
      "product": "Portable Puzzle Collection",
      "cwe": "CWE-190",
      "title": "An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24288"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-23789",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 850 firmware",
      "cwe": "CWE-415",
      "title": "An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23789"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-12518",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logitech",
      "product": "Logi Options+",
      "cwe": "CWE-269",
      "title": "Local privilege escalation in the Logi Options+ updater service on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12518"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-33963",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1330 firmware",
      "cwe": "CWE-121",
      "title": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33963"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-16726",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "panasonic",
      "product": "PANATERM v6",
      "cwe": "CWE-120",
      "title": "Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16726"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2023-24286",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simon Tatham",
      "product": "Portable Puzzle Collection",
      "cwe": "CWE-120",
      "title": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24286"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-23788",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.00992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1280 firmware",
      "cwe": "CWE-122",
      "title": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23788"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-33964",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.0075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1580 firmware",
      "cwe": "CWE-822",
      "title": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33964"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-33957",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1580 firmware",
      "cwe": "CWE-787",
      "title": "An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33957"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-33962",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 850 firmware",
      "cwe": "CWE-125",
      "title": "An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33962"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-33966",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1330 firmware",
      "cwe": "CWE-215",
      "title": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33966"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-23787",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1280 firmware",
      "cwe": "CWE-416",
      "title": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23787"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-23790",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1280 firmware",
      "cwe": "CWE-415",
      "title": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23790"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-23791",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1280 firmware",
      "cwe": "CWE-787",
      "title": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23791"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2023-37366",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.0054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 850 firmware",
      "cwe": "CWE-835",
      "title": "An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-37366"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-33956",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1330 firmware",
      "cwe": "CWE-787",
      "title": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33956"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-33960",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1330 firmware",
      "cwe": "CWE-787",
      "title": "An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33960"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-33967",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1330 firmware",
      "cwe": "CWE-787",
      "title": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33967"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-33968",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1330 firmware",
      "cwe": "CWE-125",
      "title": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33968"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-23786",
      "cvss_base": 2.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00081,
      "epss_percentile": 0.00204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung",
      "product": "Exynos 1280 firmware",
      "cwe": "CWE-367",
      "title": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23786"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-82434",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Nimbus",
      "cwe": "CWE-522",
      "title": "Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82434"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-16338",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-73",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16338"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-20353",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-664",
      "title": "Cisco Secure Email Gateway Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20353"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-54333",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theopolis",
      "product": "uefi-firmware-parser",
      "cwe": "CWE-787",
      "title": "UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54333"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-54334",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theopolis",
      "product": "uefi-firmware-parser",
      "cwe": "CWE-787",
      "title": "UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54334"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-55209",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "equinor",
      "product": "resdata",
      "cwe": "CWE-120",
      "title": "resdata insufficiently validates untrusted GRDECL files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55209"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-57123",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonaiagents",
      "cwe": "CWE-306",
      "title": "PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57123"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-57124",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-78",
      "title": "PraisonAI UI MCP connect endpoint allows unauthenticated local command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57124"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-57125",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-306",
      "title": "PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57125"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-57127",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-306",
      "title": "praisonai: recipe serve auth middleware silently disables itself when no secret is set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57127"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-57131",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "praisonai: Jobs API exposes agent-execution endpoints with no authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57131"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-59178",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esphome",
      "product": "device-builder",
      "cwe": "CWE-306",
      "title": "ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59178"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-65414",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65414"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-73370",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-863",
      "title": "Apache Syncope: Cross-Realm boundaries reconciliation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73370"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-73470",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-269",
      "title": "Apache Syncope: Delegating users can grant unowned Roles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73470"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-73579",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-863",
      "title": "Apache Syncope: Non-recursive Any search could skip Realms restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73579"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-73668",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-863",
      "title": "Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73668"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-75030",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-862",
      "title": "Apache Syncope: Incomplete authorization checks for Group members deprovisioning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75030"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-76440",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-23",
      "title": "Cisco Secure Email Gateway Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76440"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-76441",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Email and Web Manager",
      "cwe": "CWE-284",
      "title": "Cisco Secure Email Gateway Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76441"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-76443",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-707",
      "title": "Cisco Secure Email Gateway Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76443"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-77051",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-89",
      "title": "Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77051"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-77181",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-863",
      "title": "Apache Syncope: ClientApp update entitlement not effective",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77181"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-78330",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-266",
      "title": "Apache Syncope: Privilege escalation for admin user via JWT authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78330"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-82232",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-89",
      "title": "Apache Syncope: SQL injection via sort parameter in Task search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82232"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-82431",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Client",
      "cwe": "CWE-863",
      "title": "Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82431"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-82435",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Worker",
      "cwe": "CWE-789",
      "title": "Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82435"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-82439",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm DRPC",
      "cwe": "CWE-770",
      "title": "Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82439"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-86460",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-89",
      "title": "Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86460"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-90898",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maximhq",
      "product": "Bifrost",
      "cwe": "CWE-284",
      "title": "Bifrost unauthenticated remote code execution via MCP stdio client registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90898"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-12944",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Incomplete Security Scanner Blocklist Enables Network-Based Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12944"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-21391",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ping Identity",
      "product": "PingAM",
      "cwe": "CWE-290",
      "title": "Improper Claim Validation in PingAM OIDC Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21391"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-90937",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-93",
      "title": "froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90937"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-67399",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "WHMCS",
      "cwe": "CWE-502",
      "title": "Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67399"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-90919",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-502",
      "title": "LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90919"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-90942",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "casdoor",
      "product": "casdoor",
      "cwe": "CWE-863",
      "title": "Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90942"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-90943",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parallax",
      "product": "filament-comments",
      "cwe": "CWE-79",
      "title": "parallax filament-comments through 3.0.0 Stored XSS via Comment Body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90943"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-90945",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crawlab-team",
      "product": "crawlab",
      "cwe": "CWE-321",
      "title": "Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90945"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-90961",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90961"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-12258",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hiperdino",
      "product": "REST API",
      "cwe": "CWE-284",
      "title": "Inadequate access control in the Hiperdino REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12258"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-57578",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "riganti",
      "product": "dotvvm",
      "cwe": "CWE-862",
      "title": "DotVVM: Missing authorization in AuthorizeActionFilter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57578"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-50006",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "julien040",
      "product": "anyquery",
      "cwe": "CWE-22",
      "title": "Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50006"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-53713",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "gateway",
      "cwe": "CWE-20",
      "title": "Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53713"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-57145",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57145"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-61534",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "confetti",
      "product": "yayson",
      "cwe": "CWE-1321",
      "title": "Yayson: Prototype pollution in the Store/LegacyStore deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61534"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-78299",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Embedded CDT (C/C++ Development Tools)",
      "cwe": "CWE-22",
      "title": "In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78299"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-82441",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Nimbus",
      "cwe": "CWE-20",
      "title": "Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82441"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-87785",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-290",
      "title": "Apache Syncope: JWT subject spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87785"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-87802",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-347",
      "title": "Apache Syncope: SRA OAuth2 JWT signature verification bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87802"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-13293",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-502",
      "title": "IBM MQ Java messaging is vulnerable to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13293"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-16428",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-94",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16428"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-16466",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16466"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-16673",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": null,
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16673"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-43692",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-20",
      "title": "A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote user may cause an unexpected app termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43692"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-55416",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-89",
      "title": "Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concatenation of User-Controlled Configuration Fields Without Parameterization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55416"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-61701",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cesargb",
      "product": "laravel-magiclink",
      "cwe": "CWE-502",
      "title": "Laravel MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61701"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-72524",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Doris",
      "cwe": "CWE-863",
      "title": "Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72524"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-82428",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Client",
      "cwe": "CWE-22",
      "title": "Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82428"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-89023",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeAtelier",
      "product": "Domain For Sale",
      "cwe": "CWE-862",
      "title": "ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89023"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-90938",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langbot-app",
      "product": "LangBot",
      "cwe": "CWE-306",
      "title": "LangBot through 0.4.17 Unauthenticated Plugin Registration via WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90938"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-90944",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-306",
      "title": "Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90944"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-49250",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "edmundhung",
      "product": "conform",
      "cwe": "CWE-407",
      "title": "Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49250"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-68489",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk extension \"Ruby\"",
      "cwe": "CWE-96",
      "title": "Static Code Injection in Plesk extensions \"Ruby\" before 1.6.6 and \"Node.js Toolkit\" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68489"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-82028",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "absmach",
      "product": "magistrala",
      "cwe": "CWE-89",
      "title": "Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82028"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-84445",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grpc",
      "product": "grpc-go",
      "cwe": "CWE-129",
      "title": "gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers in the xDS servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84445"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-89180",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinking Software Technology",
      "product": "EFence",
      "cwe": "CWE-89",
      "title": "Thinking Software Technology｜EFence - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89180"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-90934",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espocrm",
      "product": "espocrm",
      "cwe": "CWE-863",
      "title": "EspoCRM before 10.0.4 Field-level Security Bypass via Attendees",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90934"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-90946",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncFuncAI",
      "product": "deepwiki-open",
      "cwe": "CWE-73",
      "title": "DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90946"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-91080",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adnanh",
      "product": "webhook",
      "cwe": "CWE-770",
      "title": "webhook through 2.8.3 Memory Exhaustion via Oversized Request Body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91080"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-91144",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zfile-dev",
      "product": "zfile",
      "cwe": "CWE-639",
      "title": "ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91144"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-91200",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devspace",
      "product": "devspace",
      "cwe": "CWE-22",
      "title": "DevSpace through 6.3.21 Path Traversal via tar extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91200"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-7848",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alior Bank",
      "product": "raty",
      "cwe": "CWE-89",
      "title": "SQL Injection in Alior Bank raty PrestaShop module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7848"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-15600",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alior Bank",
      "product": "raty",
      "cwe": "CWE-89",
      "title": "SQL Injection in Alior Bank raty PrestaShop module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15600"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-54628",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "julien040",
      "product": "anyquery",
      "cwe": "CWE-284",
      "title": "Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54628"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-57122",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-345",
      "title": "PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57122"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-78375",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder (Free and Pro) extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78375"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-86830",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "iam-identity-center-team",
      "cwe": "CWE-266",
      "title": "Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86830"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-90932",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-73",
      "title": "LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90932"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-20773",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ping Identity",
      "product": "PingFederate",
      "cwe": "CWE-863",
      "title": "Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20773"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-55072",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-20",
      "title": "Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55072"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-57126",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-918",
      "title": "praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57126"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-81301",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ekia",
      "product": "File Manager",
      "cwe": "CWE-926",
      "title": "Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81301"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-90702",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M921",
      "cwe": "CWE-77",
      "title": "D-Link DWR-M921 formDiskFormat system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90702"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-90703",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M921",
      "cwe": "CWE-77",
      "title": "D-Link DWR-M921 formDiskCreateShare system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90703"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2024-58383",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-732",
      "title": "Froxlor before 2.2.0 Insecure File Permissions mysql.conf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58383"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-54447",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberjunky",
      "product": "python-garminconnect",
      "cwe": "CWE-732",
      "title": "garminconnect: Insecure Permission Assignment for Garmin OAuth Token Store",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54447"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-82049",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-59",
      "title": "tarfile extraction filters allow file modification and content disclosure via hard link to symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82049"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-86836",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Ankaios",
      "cwe": "CWE-276",
      "title": "In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86836"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-90895",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-150",
      "title": "MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90895"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-55451",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "locize",
      "product": "gettext-converter",
      "cwe": "CWE-1321",
      "title": "gettext-converter: Prototype pollution in js2i18next() via crafted translation keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55451"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-17467",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Data System (Yosemite 1.0)",
      "cwe": "CWE-327",
      "title": "Vulnerabilities exists in IBM Cloud Pak for Data System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17467"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-34151",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xwiki",
      "product": "xwiki-platform",
      "cwe": "CWE-24",
      "title": "XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34151"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-57132",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-287",
      "title": "PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57132"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-57577",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "riganti",
      "product": "dotvvm",
      "cwe": "CWE-1333",
      "title": "DotVVM: ReDOS in routing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57577"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-65838",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zalando",
      "product": "skipper",
      "cwe": "CWE-754",
      "title": "Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65838"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-85921",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-415",
      "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85921"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-90896",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MarcosCamara01",
      "product": "Ecommerce Template",
      "cwe": "CWE-306",
      "title": "Missing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PII",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90896"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-16335",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16335"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-25687",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-366",
      "title": "ZCC race condition in ZPA tunnel handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25687"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-54178",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-22",
      "title": "backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54178"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-54182",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-20",
      "title": "backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54182"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-57130",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonaiagents",
      "cwe": "CWE-20",
      "title": "PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57130"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-59569",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-20",
      "title": "Android ZCC VPN API method privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59569"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-82432",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Nimbus",
      "cwe": "CWE-863",
      "title": "Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82432"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-82438",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Webapp",
      "cwe": "CWE-346",
      "title": "Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82438"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-17133",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-78",
      "title": "IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17133"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-17156",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-502",
      "title": "IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17156"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-17416",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-502",
      "title": "IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17416"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-19624",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "NetworkManager-l2tp",
      "cwe": "CWE-88",
      "title": "NetworkManager-l2tp: local privilege escalation via ipsec.conf injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19624"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-43689",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-862",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43689"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-43691",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43691"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-43783",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43783"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-43786",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-280",
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43786"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-64701",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-280",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64701"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-64712",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64712"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-65362",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65362"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-82427",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Nimbus",
      "cwe": "CWE-22",
      "title": "Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82427"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-82429",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Worker Launcher",
      "cwe": "CWE-367",
      "title": "Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82429"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-82430",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Worker Launcher",
      "cwe": "CWE-367",
      "title": "Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82430"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-84505",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84505"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-84568",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "title": "A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84568"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-84631",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-280",
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84631"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-85892",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-362",
      "title": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85892"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-86917",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-280",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86917"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-90894",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Parallels",
      "product": "Parallels Desktop for Mac",
      "cwe": "CWE-78",
      "title": "Parallels Desktop local privilege escalation via appliance extract argument injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90894"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-90947",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-787",
      "title": "Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90947"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-90948",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-787",
      "title": "Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90948"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-90949",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-787",
      "title": "Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90949"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-16432",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-611",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities due to open source software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16432"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-19499",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-122",
      "title": "Buffer overflow in strfmon and strfmon_l right-justification padding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19499"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-47701",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-operator",
      "cwe": "CWE-200",
      "title": "OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47701"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-54155",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "node-opcua",
      "product": "node-opcua",
      "cwe": "CWE-347",
      "title": "node-opcua: Missing nonce verification in UserNameIdentityToken authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54155"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-55253",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langchain-mongodb",
      "cwe": "CWE-943",
      "title": "LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55253"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-73496",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Arbitrary server-side file read via attachment upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73496"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-54087",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EasyCorp",
      "product": "EasyAdminBundle",
      "cwe": "CWE-79",
      "title": "EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54087"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-54175",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-620",
      "title": "backpack/crud: Unverified password change in MyAccountController via mass assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54175"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-54180",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-639",
      "title": "backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54180"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-90930",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-59",
      "title": "File Browser through 2.63.23 Path Traversal via Symlink Alias",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90930"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-15955",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-22",
      "title": "IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15955"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-19290",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling File Gateway",
      "cwe": "CWE-284",
      "title": "IBM Sterling File Gateway is Vulnerable to Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19290"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-28960",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "title": "A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28960"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-50270",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-java",
      "cwe": "CWE-770",
      "title": "dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50270"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-50276",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-rb",
      "cwe": "CWE-770",
      "title": "dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50276"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-53659",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4k",
      "product": "http4k",
      "cwe": "CWE-409",
      "title": "http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53659"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-53752",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plutext",
      "product": "docx4j",
      "cwe": "CWE-674",
      "title": "docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53752"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-54156",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "node-opcua",
      "product": "node-opcua",
      "cwe": "CWE-770",
      "title": "node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54156"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-54567",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jugmac00",
      "product": "flask-reuploaded",
      "cwe": "CWE-178",
      "title": "Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54567"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-54629",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "julien040",
      "product": "anyquery",
      "cwe": "CWE-22",
      "title": "Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54629"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-54632",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sipsorcery-org",
      "product": "sipsorcery",
      "cwe": "CWE-20",
      "title": "SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54632"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-55091",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joaonuno",
      "product": "flat-to-nested-js",
      "cwe": "CWE-915",
      "title": "flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55091"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-57119",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57119"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-57129",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonaiagents",
      "cwe": "CWE-22",
      "title": "PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57129"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-57579",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AlchemyCMS",
      "product": "alchemy_cms",
      "cwe": "CWE-862",
      "title": "Alchemy: Unauthenticated nested page API leaks restricted & unpublished content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57579"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-59570",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "Client Connector",
      "cwe": "CWE-20",
      "title": "Android ZCC denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59570"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-59960",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argos-ci",
      "product": "argos-javascript",
      "cwe": "CWE-78",
      "title": "Argos JavaScript: CI Branch Name OS Command Injection in @argos-ci/core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59960"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-65364",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65364"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-73178",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-200",
      "title": "Apache Syncope: JWT Access Token takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73178"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-73236",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-863",
      "title": "Apache Syncope: Cross-Realm authorization bypass in delegated administration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73236"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-76442",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-1284",
      "title": "Cisco Secure Email Gateway Security Hardening Release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76442"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-78336",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-201",
      "title": "Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78336"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-84553",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-400",
      "title": "A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84553"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-87779",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-532",
      "title": "Apache Syncope: AES Secret Key disclosure via log output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87779"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-53714",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "gateway",
      "cwe": "CWE-306",
      "title": "Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53714"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-70658",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pay-rails",
      "product": "pay",
      "cwe": "CWE-208",
      "title": "pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70658"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-73494",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4s",
      "product": "blaze",
      "cwe": "CWE-444",
      "title": "blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73494"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-18116",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workflow Approval Notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18116"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-18117",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18117"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-47253",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "julien040",
      "product": "anyquery",
      "cwe": "CWE-22",
      "title": "Anyquery: Path Traversal in `clear_plugin_cache` Allows Arbitrary Directory Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47253"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-56839",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI Code agent tools fail open without a workspace boundary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56839"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-73195",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-116",
      "title": "Apache Syncope: CSV export spreadsheet formula injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73195"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-81900",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeight)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81900"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-81901",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing authorization in the `PUT /pages/{cID}` endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81901"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-90929",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-863",
      "title": "File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90929"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-8821",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "Playbooks run owner channel membership permission bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8821"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-12756",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Business Automation Workflow containers and traditional",
      "cwe": "CWE-611",
      "title": "Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12756"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-13107",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Business Automation Workflow containers and traditional",
      "cwe": "CWE-611",
      "title": "Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13107"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-13275",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-611",
      "title": "IBM MQ Managed File Transfer is vulnerable to XML external entity injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13275"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-13285",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-611",
      "title": "IBM MQ Managed File Transfer is vulnerable to XML external entity injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13285"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-13287",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-611",
      "title": "IBM MQ Managed File Transfer is vulnerable to XML external entity injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13287"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-19816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "PackageKit",
      "cwe": "CWE-863",
      "title": "PackageKit: dnf5 backend ignores SIMULATE on RepoRemove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19816"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-77884",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brain Trust",
      "product": "Gallery - Private Photo Vault",
      "cwe": "CWE-552",
      "title": "Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77884"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-81902",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81902"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-82035",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PyMuPDF",
      "product": "PyMuPDF",
      "cwe": "CWE-22",
      "title": "PyMuPDF 1.28.2 Path Traversal via extract_objects() Font Branch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82035"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-90927",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-400",
      "title": "filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90927"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-90928",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-400",
      "title": "File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90928"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-90933",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-862",
      "title": "laradashboard through 1.2.2 Missing Authorization via License API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90933"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-90939",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "201206030",
      "product": "novel-plus",
      "cwe": "CWE-862",
      "title": "novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90939"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-91145",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Activiti",
      "product": "Activiti",
      "cwe": "CWE-917",
      "title": "Activiti through 7.1.0.M6 Expression Injection via Mail Task",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91145"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-91197",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowable",
      "product": "flowable-engine",
      "cwe": "CWE-611",
      "title": "Flowable flowable-engine through 8.0.0 XXE via ProcessDiagramLayoutFactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91197"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-18119",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline block custom style values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18119"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-81564",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder (Free and Pro) extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81564"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-81903",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81903"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-54150",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "muxinc",
      "product": "next-video",
      "cwe": "CWE-22",
      "title": "next-video: Unauthenticated arbitrary file read via /api/video request handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54150"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-54559",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmusphinx",
      "product": "pocketsphinx",
      "cwe": "CWE-119",
      "title": "PocketSphinx: Buffer overflows in language and acoustic model loading code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54559"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-55795",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "commerce",
      "cwe": "CWE-307",
      "title": "Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55795"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-79700",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder (Pro) extension for Joomla",
      "cwe": "CWE-807",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79700"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-79701",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder (Pro) extension for Joomla",
      "cwe": "CWE-807",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79701"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-81565",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder (Free and Pro) extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81565"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-89021",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-22",
      "title": "MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89021"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-90707",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90707"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-90809",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-74",
      "title": "HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90809"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-90819",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2aproject",
      "product": "a2a-java",
      "cwe": "CWE-93",
      "title": "a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java BasePushNotificationSender.dispatchNotification response splitting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90819"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-90840",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Blood Donor Management System",
      "cwe": "CWE-287",
      "title": "PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90840"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-90841",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Blood Donor Management System",
      "cwe": "CWE-89",
      "title": "PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90841"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-90940",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "201206030",
      "product": "novel-plus",
      "cwe": "CWE-1392",
      "title": "novel-plus through 5.3.3 Default Cache Management Password in the Front Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90940"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-91081",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "suitenumerique",
      "product": "docs",
      "cwe": "CWE-918",
      "title": "Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91081"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-91143",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "snail007",
      "product": "goproxy",
      "cwe": "CWE-288",
      "title": "goproxy through 15.3 Authentication Bypass via CONNECT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91143"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-91198",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "growthbook",
      "product": "growthbook",
      "cwe": "CWE-201",
      "title": "GrowthBook through 5.0.1 Information Disclosure via Public Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91198"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2025-24890",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitoxideLabs",
      "product": "gitoxide",
      "cwe": "CWE-283",
      "title": "gix-sec safe.directory protections absent for elevated administrators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24890"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-12985",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-601",
      "title": "Mattermost DCR redirect URI allowlist bypass via improper URL component validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12985"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-13265",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-611",
      "title": "IBM MQ Managed File Transfer REST API is vulnerable to XML external entity injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13265"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-14986",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transaction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14986"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-16147",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16147"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-53495",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-400",
      "title": "containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53495"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-55837",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbt-labs",
      "product": "dbt-mcp",
      "cwe": "CWE-200",
      "title": "dbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55837"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-90890",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASRock",
      "product": "ASRock Polychrome SYNC/RGB for MB",
      "cwe": "CWE-822",
      "title": "ASRock｜ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90890"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-90891",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASRock",
      "product": "ASRock Polychrome SYNC/RGB for MB",
      "cwe": "CWE-1256",
      "title": "ASRock｜ASRock Polychrome SYNC/RGB software utility - Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90891"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-53708",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "mcp-context-forge",
      "cwe": "CWE-350",
      "title": "ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53708"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-54177",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-434",
      "title": "backpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54177"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-5132",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-409",
      "title": "Unbounded zlib decompression in Calls SDP WebSocket messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5132"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-9812",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-639",
      "title": "Missing property field ownership validation in Playbooks run property update endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9812"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-12759",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Business Automation",
      "cwe": "CWE-400",
      "title": "Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12759"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-12765",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12765"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-12767",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12767"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-15396",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15396"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-15412",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-601",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15412"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-15634",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15634"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-15814",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-409",
      "title": "Uploading a crafted image causes excessive memory allocation in the Mattermost Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15814"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-15893",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-617",
      "title": "Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15893"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-16187",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-862",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16187"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-16702",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-476",
      "title": "IBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16702"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-17463",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-400",
      "title": "IBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17463"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-50157",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "auth0",
      "product": "symfony",
      "cwe": "CWE-598",
      "title": "Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50157"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-53716",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "gateway",
      "cwe": "CWE-789",
      "title": "Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53716"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-53717",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "gateway",
      "cwe": "CWE-789",
      "title": "Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53717"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-53719",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "gateway",
      "cwe": "CWE-476",
      "title": "Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53719"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-54176",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-287",
      "title": "backpack/crud: MyAccountController allows changing the login email without a current-password check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54176"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-54723",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devpi",
      "product": "devpi",
      "cwe": "CWE-304",
      "title": "devpi: Database contents leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54723"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-57115",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-918",
      "title": "PraisonAI: SpiderTools redirect-target SSRF protection bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57115"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-57120",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "praisonaiagents",
      "cwe": "CWE-693",
      "title": "PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57120"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-57570",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-862",
      "title": "backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57570"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-68570",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Doris",
      "cwe": "CWE-863",
      "title": "Apache Doris: Authorization bypass leading to unauthorized data access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68570"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-73497",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-918",
      "title": "MCP Atlassian is a Model Context Protocol (MCP): DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826): unauthenticated SSRF to cloud metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73497"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-77147",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-94",
      "title": "Apache Syncope: Groovy Sandbox escape for empty CommandArgs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77147"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-82426",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Nimbus",
      "cwe": "CWE-22",
      "title": "Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82426"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-82433",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Nimbus",
      "cwe": "CWE-522",
      "title": "Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82433"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-84179",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Nimbus",
      "cwe": "CWE-200",
      "title": "Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84179"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-84538",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-20",
      "title": "A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84538"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-86879",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "title": "A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. A remote attacker may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86879"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-91181",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Data Retention Teams Endpoint Leaks Private Team Invite ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91181"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-4103",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Control Plane",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4103"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-16185",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-862",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16185"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-53718",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "gateway",
      "cwe": "CWE-862",
      "title": "Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53718"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-14275",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Family",
      "cwe": "CWE-78",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14275"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-14276",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Family",
      "cwe": "CWE-78",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14276"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-14277",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Family",
      "cwe": "CWE-78",
      "title": "IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14277"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-54452",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "doyensec",
      "product": "safeurl",
      "cwe": "CWE-918",
      "title": "safeurl: Missing IPv6 CIDR Ranges in Blocklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54452"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-88819",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Data Plane Core",
      "cwe": "CWE-290",
      "title": "In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88819"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-90842",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Blood Donor Management System",
      "cwe": "CWE-313",
      "title": "PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90842"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-91079",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hcengineering",
      "product": "platform",
      "cwe": "CWE-918",
      "title": "Huly Platform through 0.7.426 SSRF via Print Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91079"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-19543",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-20",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19543"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-55073",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kozea",
      "product": "WeasyPrint",
      "cwe": "CWE-918",
      "title": "WeasyPrint restrictive URL fetcher bypass allows local file read and SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55073"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-55846",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allure-framework",
      "product": "allure2",
      "cwe": "CWE-22",
      "title": "Allure: Path Traversal in Allure Report HTTP Server Allows Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55846"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-55093",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sonos",
      "product": "tract",
      "cwe": "CWE-125",
      "title": "tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55093"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-55832",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sonos",
      "product": "tract",
      "cwe": "CWE-22",
      "title": "Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55832"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-55847",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allure-framework",
      "product": "allure2",
      "cwe": "CWE-79",
      "title": "Allure: Stored XSS via unescaped ANSI helper in Allure report status message/trace rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55847"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-73191",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-601",
      "title": "Apache Syncope: CAS service URL injection via Forwarded HTTP headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73191"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-78318",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-79",
      "title": "Apache Syncope: Unauthenticated reflected XSS in Console and Enduser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78318"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-7208",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yealink",
      "product": "SIP-T33G",
      "cwe": "CWE-362",
      "title": "Yealink SIP-T33G < 124.87.0.0 Race Condition via Diagnostic File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7208"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-18069",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-367",
      "title": "IBM i is Affected By A Race Condition Vulnerability in SQL Query Engine []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18069"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-15924",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr sockets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15924"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-16435",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-650",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16435"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-55235",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langgraph-api",
      "cwe": "CWE-287",
      "title": "langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55235"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-55236",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langgraph-api",
      "cwe": "CWE-285",
      "title": "langgraph-api: Incomplete assistant authorization in LangGraph Server run creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55236"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-73449",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-290",
      "title": "On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73449"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-55102",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyndryl-open-source",
      "product": "hashi-vault-js",
      "cwe": "CWE-209",
      "title": "hashi-vault-js: Vault token and secret values exposed in thrown errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55102"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-54246",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zalando",
      "product": "skipper",
      "cwe": "CWE-306",
      "title": "Skipper routesrv-no-auth: All routesrv API Endpoints Lack Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54246"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-19542",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-121",
      "title": "Stack-based out-of-bounds write in tdelete during tree rebalancing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19542"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-75944",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-459",
      "title": "A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75944"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-76081",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-193",
      "title": "ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76081"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-82920",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Mattermost ABAC parent policy bypass via policy update endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82920"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-90701",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "subhajitkhan",
      "product": "online-clinic-management-system",
      "cwe": "CWE-74",
      "title": "subhajitkhan online-clinic-management-system listdoctor.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90701"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-90708",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yot",
      "product": "CMS",
      "cwe": "CWE-74",
      "title": "Yot CMS Cookie global.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90708"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-90710",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taisan",
      "product": "tarzan-cms",
      "cwe": "CWE-918",
      "title": "taisan tarzan-cms Theme Download Function ThemeService.java openConnection server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90710"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-90715",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marcobambini",
      "product": "Gravity",
      "cwe": "CWE-189",
      "title": "marcobambini Gravity udp json-parser gravity_json.c integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90715"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-90784",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dvidelabs",
      "product": "flatcc",
      "cwe": "CWE-401",
      "title": "Dvidelabs flatcc semantics.c fb_clear_parser memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90784"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-90785",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dvidelabs",
      "product": "flatcc",
      "cwe": "CWE-617",
      "title": "Dvidelabs flatcc Struct Analysis semantics.c analyze_struct assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90785"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-90786",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dvidelabs",
      "product": "flatcc",
      "cwe": "CWE-617",
      "title": "Dvidelabs flatcc Duplicate Symbol semantics.c align_order_members assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90786"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-90787",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soarkey",
      "product": "StudentManagement",
      "cwe": "CWE-266",
      "title": "Soarkey StudentManagement Registration Workflow register.html RegisterServlet.doPost privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90787"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-90789",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90789"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-90805",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "subhajitkhan",
      "product": "online-clinic-management-system",
      "cwe": "CWE-74",
      "title": "subhajitkhan online-clinic-management-system doctorlogin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90805"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-90995",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Sssd: sssd: local denial of service due to null pointer dereference in pam responder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90995"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-7884",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cognos Analytics",
      "cwe": "CWE-79",
      "title": "IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7884"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-12758",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Business Automation",
      "cwe": "CWE-862",
      "title": "Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12758"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-12766",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12766"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-15887",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-918",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15887"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-16186",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-79",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16186"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-17047",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-352",
      "title": "IBM Db2 Mirror for i is vulnerable to Cross-Site Request Forgery []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17047"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-17628",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-287",
      "title": "Langflow is affected by improper authentication due to missing password verification in the password reset endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17628"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-19273",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-287",
      "title": "The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19273"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-54181",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-79",
      "title": "backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54181"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-78415",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling Secure Proxy",
      "cwe": "CWE-79",
      "title": "IBM Sterling Secure Proxy is vulnerable to multiple issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78415"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-91021",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trilium",
      "product": "Trillium Notes",
      "cwe": "CWE-79",
      "title": "CVE-2026-91021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91021"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-10556",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-754",
      "title": "Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10556"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-16188",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-117",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16188"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-18065",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-290",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18065"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-47256",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-collector-contrib",
      "cwe": "CWE-22",
      "title": "OpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47256"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-53496",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mattiasw",
      "product": "ExifReader",
      "cwe": "CWE-248",
      "title": "ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53496"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-53715",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "gateway",
      "cwe": "CWE-362",
      "title": "Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53715"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-54529",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smithyhq",
      "product": "sqladmin",
      "cwe": "CWE-20",
      "title": "SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54529"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-57497",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quic-go",
      "product": "webtransport-go",
      "cwe": "CWE-770",
      "title": "webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57497"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-57581",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "riganti",
      "product": "dotvvm",
      "cwe": "CWE-434",
      "title": "DotVVM: Unrestricted file upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57581"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-89020",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-121",
      "title": "MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89020"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-90790",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2aproject",
      "product": "a2a-python",
      "cwe": "CWE-918",
      "title": "a2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch_notification server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90790"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-90806",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DjangoCRM",
      "product": "django-crm",
      "cwe": "CWE-862",
      "title": "DjangoCRM django-crm Bulk Case Update bulk_views.py BulkUpdateCasesView authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90806"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-90808",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-183",
      "title": "HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90808"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-90816",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FFmpeg",
      "cwe": "CWE-404",
      "title": "FFmpeg Duration hlsproto.c parse_playlist denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90816"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-90820",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2aproject",
      "product": "a2a-java",
      "cwe": "CWE-862",
      "title": "a2aproject a2a-java AuthorizationRequestHandlerDecorator.java AuthorizationRequestHandlerDecorator.onListTasks authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90820"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-90935",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-285",
      "title": "Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90935"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-90936",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-200",
      "title": "Froxlor before 2.3.7 Information Disclosure via customer_email.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90936"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-90941",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "201206030",
      "product": "novel-plus",
      "cwe": "CWE-862",
      "title": "novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90941"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-91146",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jointakahe",
      "product": "takahe",
      "cwe": "CWE-79",
      "title": "Takahe through 0.11.0 Cross-Site Scripting via javascript: URL Scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91146"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-91199",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "refly-ai",
      "product": "refly",
      "cwe": "CWE-918",
      "title": "Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91199"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-91201",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arc53",
      "product": "DocsGPT",
      "cwe": "CWE-346",
      "title": "DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91201"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-19280",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-787",
      "title": "IBM i is Affected By Multiple Vulnerabilities in PASE [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19280"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-86876",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandboxed process may be able to circumvent sandbox restrictions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86876"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-81566",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder (Free and Pro) extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81566"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-90893",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-352",
      "title": "MISP UserSettingsController CSRF Protection Bypass on setTheme, setHomePage, and eventIndexColumnToggle Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90893"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-90931",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-79",
      "title": "LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90931"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-90957",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP: Stored XSS via Inline-Served SVG Organisation Logos and Report Pictures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90957"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-10542",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-639",
      "title": "Playbooks channel action update validation issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10542"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-55244",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lmfit",
      "product": "asteval",
      "cwe": "CWE-248",
      "title": "ASTEVAL: Sandbox Escape via BaseException Subclasses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55244"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-75015",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-522",
      "title": "Apache Syncope: Nested secrets leak cleartext into audit records readable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75015"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-77883",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-202",
      "title": "Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77883"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-16189",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-117",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16189"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-15923",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-835",
      "title": "Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15923"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-16148",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-666",
      "title": "Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy delayable work item",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16148"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-90955",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-223",
      "title": "MISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model Load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90955"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-11993",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-770",
      "title": "Fix authenticated members disabling file content indexing server-wide via extraction pool exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11993"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-12882",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-407",
      "title": "Mattermost Markdown autolink parsing denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12882"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-13417",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-754",
      "title": "Boards plugin denial of service via unvalidated block fields.properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13417"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-14259",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "Board archive import bypasses team board creation permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14259"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-14344",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "Inconsistent authorization checks in Mattermost Boards endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14344"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-18251",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-1385",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18251"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-18515",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-22",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18515"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-54247",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zalando",
      "product": "skipper",
      "cwe": "CWE-770",
      "title": "Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54247"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-57128",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-306",
      "title": "PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57128"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-65352",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-642",
      "title": "An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65352"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-65355",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-642",
      "title": "An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65355"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-75792",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling Secure Proxy",
      "cwe": "CWE-285",
      "title": "IBM Sterling Secure Proxy is vulnerable to multiple issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75792"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-82437",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Storm Logviewer",
      "cwe": "CWE-862",
      "title": "Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82437"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-84518",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-642",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84518"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-86348",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-704",
      "title": "MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86348"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-86349",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-407",
      "title": "Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86349"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-12763",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-306",
      "title": "Langflow is vulnerable to authentication bypass and insufficient session expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12763"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-18151",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-362",
      "title": "IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18151"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-90463",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90463"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-90994",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: sssd: denial of service via malformed pam v1 requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90994"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-90996",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-191",
      "title": "Sssd: sssd: denial of service in nss responder via crafted zero-length requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90996"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-54541",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-248",
      "title": "Nimiq: Panic in TrieProof::verify via child_index unwrap on equal-length keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54541"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-54542",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-125",
      "title": "Nimiq: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54542"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-55866",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authzed",
      "product": "spicedb",
      "cwe": "CWE-863",
      "title": "SpiceDBChecks involving relations with caveats can result in unconditional permission when conditional permission is expected",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55866"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-19086",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-125",
      "title": "IBM i is Affected By Multiple Vulnerabilities in PASE [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19086"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-46696",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "octobercms",
      "product": "system",
      "cwe": "CWE-269",
      "title": "October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46696"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-49400",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "octobercms",
      "product": "october",
      "cwe": "CWE-502",
      "title": "October CMS: PHP Object Injection via Backend Widget Session Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49400"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-57583",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenZeppelin",
      "product": "contracts-wizard",
      "cwe": "CWE-94",
      "title": "OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57583"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-16190",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-862",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16190"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-44162",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fluent",
      "product": "fluent-plugin-s3",
      "cwe": "CWE-409",
      "title": "fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44162"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-82019",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TripleLift",
      "product": "video-bundle.js",
      "cwe": "CWE-79",
      "title": "TripleLift video-bundle.js DOM-based XSS via postMessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82019"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-82519",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reallysimpleplugins",
      "product": "Really Simple Security",
      "cwe": "CWE-862",
      "title": "Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82519"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-75943",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-459",
      "title": "A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75943"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-75945",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-459",
      "title": "A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75945"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-77191",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-862",
      "title": "All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77191"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-90712",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitlawb",
      "product": "openclaude",
      "cwe": "CWE-404",
      "title": "Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90712"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-90714",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marcobambini",
      "product": "Gravity",
      "cwe": "CWE-119",
      "title": "marcobambini Gravity JSON parser gravity_json.c memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90714"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-90791",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_unregister use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90791"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-90792",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-404",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90792"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-90793",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_get_name use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90793"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-90794",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box vrml_tools.c gf_sg_script_load use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90794"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-90795",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Loan Management System",
      "cwe": "CWE-79",
      "title": "itsourcecode Loan Management System navbar.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90795"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-90796",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90796"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-90807",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "NanoClaw",
      "cwe": "CWE-59",
      "title": "nanocoai NanoClaw Attachment agent-route.ts forwardAttachedFiles link following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90807"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-90810",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-266",
      "title": "cosmicstack-labs mercury-agent Shell Command Permission Check permissions.ts PermissionManager.checkShellCommand improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90810"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-90812",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-266",
      "title": "cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkShellCommand privileges assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90812"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-90813",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-179",
      "title": "cosmicstack-labs mercury-agent Shell Command Execution permissions.ts checkShellCommand validate before canonicalize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90813"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-90814",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-918",
      "title": "cosmicstack-labs mercury-agent GitHub API github.ts githubRequest server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90814"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-90815",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FFmpeg",
      "cwe": "CWE-119",
      "title": "FFmpeg Convolution Filter vf_convolution.c setup_3x3 out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90815"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-90818",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netease-youdao",
      "product": "LobsterAI",
      "cwe": "CWE-918",
      "title": "netease-youdao LobsterAI Browser Network Configuration openclawConfigSync.ts OpenClawConfigSync.buildBrowserConfig server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90818"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-90704",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M921",
      "cwe": "CWE-74",
      "title": "D-Link DWR-M921 formDiskPartition system command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90704"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-90705",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M921",
      "cwe": "CWE-77",
      "title": "D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90705"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-90706",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M921",
      "cwe": "CWE-77",
      "title": "D-Link DWR-M921 formWsc os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90706"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-90709",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yot",
      "product": "CMS",
      "cwe": "CWE-74",
      "title": "Yot CMS Admin Console admin.php eval code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90709"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-90716",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marcobambini",
      "product": "Gravity",
      "cwe": "CWE-119",
      "title": "marcobambini Gravity Number gravity_parser.c parse_number_expression out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90716"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-90788",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magicblack",
      "product": "MacCMS10",
      "cwe": "CWE-77",
      "title": "magicblack MacCMS10 Template .%40template%40default%40html%40label.html os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90788"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-90835",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "michaelliao",
      "product": "itranswarp",
      "cwe": "CWE-79",
      "title": "michaelliao itranswarp Page Content Rendering Markdown.java Markdown.toHtml cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90835"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-90713",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-404",
      "title": "vllm-project vLLM tiktoken vocab File mod.rs new denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90713"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-90801",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-119",
      "title": "GNU Binutils ld cache.c cache_bwrite buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90801"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-90802",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-404",
      "title": "GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90802"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-90803",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-119",
      "title": "GNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90803"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-90811",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cosmicstack-labs",
      "product": "mercury-agent",
      "cwe": "CWE-200",
      "title": "cosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts PermissionManager.checkShellCommand information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90811"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-90824",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box dom_events.c gf_sg_dom_event_bubble stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90824"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-90825",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_unregister use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90825"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-90827",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90827"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-90828",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-404",
      "title": "GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90828"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-90829",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-404",
      "title": "GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90829"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-90830",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-404",
      "title": "GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90830"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-90831",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-119",
      "title": "GNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90831"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-90804",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Binutils",
      "cwe": "CWE-119",
      "title": "GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90804"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-90826",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_del out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90826"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-13260",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-770",
      "title": "Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13260"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-13272",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-1385",
      "title": "Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13272"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-13276",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-79",
      "title": "Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13276"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-13277",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-601",
      "title": "Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13277"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-20683",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20683"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-28836",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28836"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-28899",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28899"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-28933",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28933"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-28934",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a malicious disk image may cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28934"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-28935",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28935"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-28937",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28937"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-28938",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28938"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-28966",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28966"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-28968",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28968"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-43664",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43664"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-43674",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43674"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-43677",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43677"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-43683",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected process termination or disclose process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43683"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-43684",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43684"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-43686",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43686"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-43687",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43687"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-43688",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43688"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-43690",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43690"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-43695",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43695"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-43696",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to capture Touch Bar content without authorization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43696"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-43697",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43697"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-43702",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43702"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-43719",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted SMB network share may lead to system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43719"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-43737",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43737"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-43741",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43741"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-43761",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a malicious disk image may cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43761"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-43762",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43762"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-43785",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to read.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43785"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-43787",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to leak sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43787"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-43788",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43788"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-43789",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43789"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-43790",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43790"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-43791",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to read arbitrary files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43791"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-43808",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43808"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-43815",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious afpfs server may lead to kernel memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43815"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-64714",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64714"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-64717",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64717"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-64736",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64736"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-64752",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64752"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-64753",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": null,
      "title": "A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64753"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-64756",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64756"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-64761",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to identify what other apps a user has installed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64761"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-64790",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64790"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-65342",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65342"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-65344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted video file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65344"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-65345",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65345"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-65348",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65348"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-65353",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65353"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-65354",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65354"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-65357",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65357"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-65358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65358"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-65359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65359"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-65360",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65360"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-65361",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65361"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-65365",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB share may disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65365"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-65369",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65369"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-65371",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65371"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-65374",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65374"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-65375",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "The issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65375"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-65376",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65376"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-65377",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65377"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-65378",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65378"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-65380",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65380"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-65381",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65381"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-65382",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65382"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-65383",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65383"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-65390",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65390"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-65391",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65391"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-65393",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Xcode",
      "cwe": null,
      "title": "A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65393"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-65395",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted image may result in memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65395"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-65398",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65398"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-65399",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An archive may be able to bypass Gatekeeper.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65399"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-65401",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state handling. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65401"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-65402",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65402"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-65403",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "This issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65403"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-65404",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application may be able to bypass Privacy preferences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65404"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-65405",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65405"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-65406",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65406"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-65407",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, tvOS 26.6, tvOS 27, visionOS 26.6, visionOS 27, watchOS 26.6, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65407"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-65408",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65408"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-65409",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65409"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-65410",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65410"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-65411",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to modify protected parts of the file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65411"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-65412",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. Processing web content may lead to a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65412"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-65413",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65413"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-65415",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65415"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-84487",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may result in disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84487"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-84489",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84489"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-84491",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84491"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-84492",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84492"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-84497",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may lead to unexpected process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84497"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-84506",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to execute arbitrary code with kernel privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84506"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-84507",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84507"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-84509",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84509"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-84510",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84510"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-84511",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted asset catalog may lead to unexpected process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84511"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-84512",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84512"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-84513",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A malicious application may be able to determine a user's current location.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84513"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-84514",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84514"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-84515",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84515"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-84516",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84516"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-84517",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84517"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-84519",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a disk image with maliciously crafted files may lead to unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84519"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-84520",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84520"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-84521",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84521"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-84522",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84522"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-84523",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or write kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84523"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-84524",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84524"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-84525",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84525"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-84526",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D scene may lead to unexpected process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84526"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-84527",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84527"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-84530",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84530"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-84531",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing maliciously crafted NTLM input may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84531"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-84532",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may cause unexpected process termination or disclose process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84532"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-84533",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An attacker in a privileged network position may be able to modify network traffic.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84533"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-84534",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. Extracting a maliciously crafted archive may allow an attacker to write arbitrary files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84534"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-84535",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84535"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-84536",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84536"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-84537",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84537"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-84540",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84540"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-84541",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84541"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-84543",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84543"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-84544",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84544"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-84546",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84546"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-84548",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted document may lead to an out-of-bounds read.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84548"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-84549",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84549"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-84550",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A race condition was addressed with additional validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84550"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-84551",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to bypass network restrictions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84551"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-84552",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84552"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-84554",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84554"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-84555",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84555"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-84556",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84556"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-84558",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84558"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-84559",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84559"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-84560",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may gain unauthorized access to Bluetooth.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84560"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-84561",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84561"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-84562",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84562"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-84563",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84563"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-84564",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may result in disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84564"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-84565",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted disk image may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84565"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-84566",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84566"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-84567",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84567"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-84569",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84569"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-84570",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84570"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-84571",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84571"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-84572",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination or read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84572"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-84573",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84573"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-84574",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Privacy preferences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84574"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-84575",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84575"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-84576",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84576"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-84577",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to bypass sandbox restrictions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84577"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-84578",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84578"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-84580",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84580"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-84581",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84581"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-84583",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84583"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-84584",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84584"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-84585",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access local network devices without user consent.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84585"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-84586",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, watchOS 27. A malicious application may be able to leak sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84586"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-84587",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84587"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-84588",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84588"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-84589",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may be able to modify Privacy preferences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84589"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-84593",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84593"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-84596",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84596"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-84597",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84597"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-84598",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a trust-paired device may be able to read and write arbitrary files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84598"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-84600",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84600"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-84601",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Apple Intelligence security prompts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84601"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-84602",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84602"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-84603",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84603"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-84606",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84606"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-84607",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84607"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-84609",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to modify protected system files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84609"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-84611",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84611"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-84612",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to read persistent device identifiers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84612"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-84615",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, tvOS 27, visionOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84615"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-84616",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84616"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-84617",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84617"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-84618",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84618"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-84619",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination or write kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84619"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-84620",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84620"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-84621",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84621"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-84622",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app with root privileges may be able to read uninitialized kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84622"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-84623",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An app may be able to fingerprint the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84623"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-84624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. A sandboxed app may be able to access restricted files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84624"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2026-84625",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84625"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2026-84626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to identify what other apps a user has installed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84626"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2026-84628",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to access the System Keychain.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84628"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-84629",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84629"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-84630",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84630"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-84632",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84632"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-84635",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": null,
      "title": "A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84635"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-84636",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84636"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-86869",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing a maliciously crafted image may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86869"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-86870",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86870"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-86878",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86878"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-86881",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86881"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-86882",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected process termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86882"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-86883",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86883"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-86884",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86884"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-86885",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An attacker in radio range may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86885"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-86886",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86886"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-86887",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to bypass certain Privacy preferences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86887"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-86888",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86888"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-86889",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to intercept network traffic.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86889"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-86890",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a locked device may be able to view sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86890"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-86891",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86891"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-86892",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86892"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-86893",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to read device name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86893"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-86894",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86894"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-86895",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86895"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-86897",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": null,
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86897"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-86898",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": null,
      "title": "A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86898"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-86900",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86900"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-86901",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86901"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-86902",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86902"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-86903",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86903"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-86904",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86904"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-86905",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86905"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-86909",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86909"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-86910",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86910"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-86911",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": null,
      "title": "This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass clickjacking protections for secure prompts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86911"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-86924",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": null,
      "title": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7. Connecting a malicious accessory may cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86924"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-76461",
      "detail": "ADDED TO KEV — CVE-2026-76461 (Cisco Secure Email). Remediation due September 17, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-23368",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-23368 (wildfly-core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-9086",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-9086 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33870",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33870 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3805",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3805 (curl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43502",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43502 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43760",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43760 (Apple macOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63769",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69250",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69250 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69251",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69251 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69252",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69252 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69253",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69253 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69254",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69254 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69255 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69256",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69256 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69257",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69257 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69258",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69258 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69259",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69259 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69262",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69262 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69263",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69263 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69264 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70470",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70470 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72708",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72708 (SPIP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72709 (SPIP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72710 (SPIP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74933",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74933 (Unknown GenieWords). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75429",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75429. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78849. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79515",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79515. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80115",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80115 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81022",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81022 (Unknown SupportCandy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-81648",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-81648 (Unknown CryptoPayment Gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85129",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85129 (Unknown Hoo Companion). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86739",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86739 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86740 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86741",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86741 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86742",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86742 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86743",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86743 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86744",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86744 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86745",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86745 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86746",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86746 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86747",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86747 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86748",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86748 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86749",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86749 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86750",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86750 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86751",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86751 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87719",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87719 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87921",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87921 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87926",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87926 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87929",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87929 (MaxSite CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88000",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88000 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88001",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88001 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88002",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88002 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88793",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88793 (Unknown YouTube Embed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88802",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88802 (Unknown MDJM Event Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89050",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89050 (Unknown Quads Ads Manager for Google AdSense). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90487 (Xuxueli xxl-job). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90490",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90490 (lenve vhr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90493",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90493 (Tonec Internet Download Manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90495 (Fengoffice Feng Office). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90497 (Fengoffice Feng Office). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90500",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90500 (lenve vhr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90502",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90502 (stilleshan ServerStatus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90505",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90505 (vvbbnn00 WARP-Clash-API). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90507",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90507 (vvbbnn00 WARP-Clash-API). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90510",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90510 (dromara orion-visor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90516",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90516 (SourceCodester School Registration and Fee System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90518",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90518 (PHPGurukul Bank Locker Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90521",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90521 (jaychouchannel Tourism-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90523 (jaychouchannel Tourism-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90526 (SourceCodester School Registration and Fee System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90543",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90543 (WWBN AVideo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90566",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90566 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90574",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90574 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90576",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90576 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90579 (cheshire-cat-ai Cheshire Cat AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90581 (cym1102 nginxWebUI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90584 (TooTallNate Java-WebSocket). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90594",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90594 (wxiaoqi Spring-Cloud-Platform). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90597",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90597 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90599",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90599 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90648",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90648 (WebAssembly wabt). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-67277",
      "detail": "DUE DATE PASSED — CVE-2026-67277 (Mikrotik RouterOS). CISA remediation deadline was September 13, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-86060",
      "detail": "DUE DATE PASSED — CVE-2026-86060 (Mikrotik RouterOS). CISA remediation deadline was September 13, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-29567",
      "detail": "RESCORED — CVE-2022-29567 (vaadin). CVSS 5.7 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-25499",
      "detail": "RESCORED — CVE-2023-25499 (vaadin). CVSS 5.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-25500",
      "detail": "RESCORED — CVE-2023-25500 (vaadin). CVSS 3.5 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-23191",
      "detail": "RESCORED — CVE-2026-23191 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56711",
      "detail": "RESCORED — CVE-2026-56711 (VideoLAN VLC media player). CVSS 8.6 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73324",
      "detail": "RESCORED — CVE-2026-73324 (VideoLAN VLC media player). CVSS 6.9 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-90604",
      "detail": "RESCORED — CVE-2026-90604 (Totolink A3002MU). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-90605",
      "detail": "RESCORED — CVE-2026-90605 (Totolink A3002MU). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-90606",
      "detail": "RESCORED — CVE-2026-90606 (Totolink A3002MU). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-63310",
      "detail": "REJECTED — CVE-2026-63310 (nltk). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-25470",
      "detail": "PATCH SHIPPED — CVE-2026-25470 (ACPT (Pro) - Custom Post Types Plugin for WordPress). Fixed in ACPT (Pro) - Custom Post Types Plugin for WordPress 2.0.52."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-50017",
      "detail": "ENRICHED — CVE-2024-50017 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-56545",
      "detail": "ENRICHED — CVE-2024-56545 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-56639",
      "detail": "ENRICHED — CVE-2024-56639 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-21651",
      "detail": "ENRICHED — CVE-2025-21651 (Linux). Received CVSS 4.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-22101",
      "detail": "ENRICHED — CVE-2025-22101 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-22103",
      "detail": "ENRICHED — CVE-2025-22103 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-23129",
      "detail": "ENRICHED — CVE-2025-23129 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-37833",
      "detail": "ENRICHED — CVE-2025-37833 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-38266",
      "detail": "ENRICHED — CVE-2025-38266 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-38591",
      "detail": "ENRICHED — CVE-2025-38591 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-71142",
      "detail": "ENRICHED — CVE-2025-71142 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23137",
      "detail": "ENRICHED — CVE-2026-23137 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23201",
      "detail": "ENRICHED — CVE-2026-23201 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23447",
      "detail": "ENRICHED — CVE-2026-23447 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23448",
      "detail": "ENRICHED — CVE-2026-23448 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-31420",
      "detail": "ENRICHED — CVE-2026-31420 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43088",
      "detail": "ENRICHED — CVE-2026-43088 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43288",
      "detail": "ENRICHED — CVE-2026-43288 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
