{
  "day": "2026-09-16",
  "boundary": "UTC calendar day",
  "published_count": 871,
  "by_severity": {
    "CRITICAL": 85,
    "HIGH": 382,
    "MEDIUM": 179,
    "LOW": 33
  },
  "kev_count": 1,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 192,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-76460",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-09-19",
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-648",
      "title": "Cisco Identity Services Engine Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76460"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-27560",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02225,
      "epss_percentile": 0.81844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection via DELETE in /api/status/data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27560"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-27561",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02225,
      "epss_percentile": 0.81844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection via GET in /api/iodd/config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27561"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-27562",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02225,
      "epss_percentile": 0.81844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection via PUT in /api/iodd/config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27562"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-27547",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection in /index.php/ajax/get_iodd_menu_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27547"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-27548",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection in /index.php/ajax/get_iodd_port_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27548"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-27549",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection in /index.php/attached_devices_tab/do_upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27549"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-27550",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection in Field_Shadow_Password Class",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27550"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-27551",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection in /index.php/ajax/parameterManage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27551"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-27554",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection in /index.php/ajax/save_iodd_parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27554"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-27558",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27558"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-27559",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02116,
      "epss_percentile": 0.80911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection via GET in /api/status/data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27559"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-27563",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02023,
      "epss_percentile": 0.79992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection via GET in /api/datastorage/data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27563"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-27564",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02023,
      "epss_percentile": 0.79992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Command Injection via PUT in /api/datastorage/data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27564"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-84408",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01073,
      "epss_percentile": 0.63236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QualitySoft Corporation",
      "product": "QND Premium",
      "cwe": "CWE-782",
      "title": "QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84408"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-27546",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00953,
      "epss_percentile": 0.59597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-288",
      "title": "Authentication Bypass in _account_log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27546"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-27565",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00941,
      "epss_percentile": 0.59232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-78",
      "title": "Remote code execution via uploading a malicious IODD file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27565"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-27556",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00861,
      "epss_percentile": 0.56745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-98",
      "title": "Local File Inclusion in /index.php/ajax/save_iodd_parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27556"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-86108",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00832,
      "epss_percentile": 0.55813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "VeloCloud Edge",
      "cwe": "CWE-78",
      "title": "Security Advisory 0181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86108"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-27555",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00826,
      "epss_percentile": 0.5565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-98",
      "title": "Local File Inclusion in /index.php/ajax/get_iodd_port_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27555"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-73447",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00756,
      "epss_percentile": 0.53407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-78",
      "title": "Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73447"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-73453",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00746,
      "epss_percentile": 0.53063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-94",
      "title": "Security Advisory 0174",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73453"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-27557",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00707,
      "epss_percentile": 0.5171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-35",
      "title": "Path Traversal in /index.php/view_uploaded_iodd_file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27557"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-92355",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00684,
      "epss_percentile": 0.50845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-22",
      "title": "In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92355"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2025-14871",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00636,
      "epss_percentile": 0.48828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14871"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-1168",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00636,
      "epss_percentile": 0.48828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1168"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-78088",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00595,
      "epss_percentile": 0.46844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contest-gallery",
      "product": "Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe",
      "cwe": "CWE-434",
      "title": "Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78088"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-88263",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.45154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XikeStor",
      "product": "SKS8310-8X",
      "cwe": "CWE-306",
      "title": "XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88263"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-27552",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.45165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-863",
      "title": "Unauthorized IODD File Upload due to Improper Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27552"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-27553",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00536,
      "epss_percentile": 0.43898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepperl+Fuchs",
      "product": "ICE2-8IOL1-G65L-V1D",
      "cwe": "CWE-497",
      "title": "Information Disclosure via Schema Path Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27553"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-81642",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81642"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-92220",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00521,
      "epss_percentile": 0.42961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-400",
      "title": "vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release_message resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92220"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-92091",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00496,
      "epss_percentile": 0.41371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-407",
      "title": "Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92091"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-8462",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.40521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openmeter",
      "product": "openmeter",
      "cwe": "CWE-89",
      "title": "OpenMeter SQL Injection in ClickHouse-backed Meter Definitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8462"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-73464",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00483,
      "epss_percentile": 0.40476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-94",
      "title": "Security Advisory 0166",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73464"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-73455",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-130",
      "title": "Security Advisory 0173",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73455"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-86792",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00453,
      "epss_percentile": 0.38432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Apache Kafka provider",
      "cwe": "CWE-470",
      "title": "Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86792"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-92216",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00444,
      "epss_percentile": 0.37788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2ui-project",
      "product": "a2ui",
      "cwe": "CWE-601",
      "title": "a2ui-project a2ui Binder generic-binder.ts openUrl redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92216"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-14349",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.36071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker – Appointment Booking and Scheduler System",
      "cwe": "CWE-862",
      "title": "TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14349"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-8030",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00414,
      "epss_percentile": 0.35099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8030"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-19248",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "qt",
      "cwe": "CWE-674",
      "title": "Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19248"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-82717",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-122",
      "title": "CNAME synthesis could lead to heap corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82717"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-92081",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00395,
      "epss_percentile": 0.33261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify",
      "product": "fastify",
      "cwe": "CWE-248",
      "title": "fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92081"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-88255",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.33146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-1289",
      "title": "mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88255"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-89186",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.33146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-524",
      "title": "mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89186"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-78252",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.3293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78252"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-89063",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-639",
      "title": "Online Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89063"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-12793",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "JetFormBuilder — Dynamic Blocks Form Builder",
      "cwe": "CWE-269",
      "title": "JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12793"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-92215",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0038,
      "epss_percentile": 0.31651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2ui-project",
      "product": "a2ui",
      "cwe": "CWE-918",
      "title": "a2ui-project a2ui FileResolver file_resolver.py httpx.get server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92215"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-81634",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.29113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-122",
      "title": "Possible heap buffer overflow during DNSSEC canonicalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81634"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-92299",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.28118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jitsi",
      "product": "@jitsi/electron-sdk",
      "cwe": "CWE-862",
      "title": "@jitsi/electron-sdk before 10.0.5 Unauthorized Screen Capture",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92299"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-79708",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79708"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-89207",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "WTV676-HB6035 Web Interface",
      "cwe": "CWE-1287",
      "title": "A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89207"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-73439",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-842",
      "title": "Security Advisory 0164",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73439"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-73445",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-20",
      "title": "Security Advisory 0167",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73445"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-7514",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7514"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-16794",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16794"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-92298",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EspoCRM",
      "product": "EspoCRM",
      "cwe": "CWE-338",
      "title": "EspoCRM through 10.0.8 Weak Token Generation via rand()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92298"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-86338",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.25176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-1220",
      "title": "Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86338"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-92217",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2ui-project",
      "product": "a2ui",
      "cwe": "CWE-913",
      "title": "a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-determined object attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92217"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-86341",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-1280",
      "title": "Access Control Check Implemented After Asset is Accessed in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86341"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-3855",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00316,
      "epss_percentile": 0.24488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-99",
      "title": "Improper Control of Resource Identifiers ('Resource Injection') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3855"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-80225",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-770",
      "title": "Possible degradation of service from continuous queries on the same TCP/DoT connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80225"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-85501",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-770",
      "title": "Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85501"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-19619",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.23015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19619"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-73461",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-266",
      "title": "Security Advisory 0163",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73461"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-73454",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-77",
      "title": "Security Advisory 0165",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73454"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-73469",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-863",
      "title": "Security Advisory 0176",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73469"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-16588",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdirectorykit",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'order_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16588"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-92247",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00294,
      "epss_percentile": 0.22081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "synaptikcms",
      "product": "synaptik-cms",
      "cwe": "CWE-284",
      "title": "synaptikcms synaptik-cms Admin File Manager file-manager.php rename unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92247"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-11984",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spacetime",
      "product": "Ad Inserter – Ad Manager & AdSense Ads",
      "cwe": "CWE-862",
      "title": "Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11984"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-82720",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-416",
      "title": "Use-after-free in DoH stream cleanup code path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82720"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2024-11222",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-11222"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-92358",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-613",
      "title": "Keycloak-services: keycloak-services: residual cross-browser account-link proof allows silent re-linking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92358"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-76550",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00273,
      "epss_percentile": 0.19706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76550"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-76551",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00273,
      "epss_percentile": 0.19706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76551"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-77860",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00272,
      "epss_percentile": 0.19665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-675",
      "title": "'serve-expired' can bypass Unbound 'wait-limit'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77860"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-92221",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00268,
      "epss_percentile": 0.19038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-74",
      "title": "gedelumbung HospitalManagement app_global_admin_model.php generate_index_pasien sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92221"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-78227",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-416",
      "title": "Use-after-free in DoQ stream output buffer on reset re-transmission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78227"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-92214",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.1761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2ui-project",
      "product": "a2ui",
      "cwe": "CWE-79",
      "title": "a2ui-project a2ui a2a-chat-canvas sanitizer-markdown-renderer-service.ts cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92214"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-86475",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Appointment Hour Booking",
      "cwe": "CWE-20",
      "title": "Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86475"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-73440",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00255,
      "epss_percentile": 0.17304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-212",
      "title": "Security Advisory 0178",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73440"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-76552",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00254,
      "epss_percentile": 0.17092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76552"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-73468",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-670",
      "title": "Security Advisory 0175",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73468"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-84439",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00251,
      "epss_percentile": 0.16684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ZooKeeper",
      "cwe": "CWE-117",
      "title": "Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84439"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-18595",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-lab",
      "product": "WP-Lister Lite for eBay",
      "cwe": "CWE-79",
      "title": "WP-Lister Lite for eBay <= 3.8.9 - Unauthenticated Stored Cross-Site Scripting via AJAX Cron Handler Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18595"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-82310",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0025,
      "epss_percentile": 0.16497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-613",
      "title": "Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82310"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-2380",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-256",
      "title": "Security Advisory 0168",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2380"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-86109",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "VeloCloud Edge",
      "cwe": "CWE-347",
      "title": "Security Advisory 0182",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86109"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-79993",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00242,
      "epss_percentile": 0.15562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ZooKeeper",
      "cwe": "CWE-862",
      "title": "Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79993"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-92213",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2ui-project",
      "product": "a2ui",
      "cwe": "CWE-74",
      "title": "a2ui-project a2ui Angular Renderer server-to-client.ts z.any injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92213"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-73436",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-125",
      "title": "Security Advisory 0171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73436"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-78472",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00231,
      "epss_percentile": 0.14125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ni WooCommerce Sales Report",
      "cwe": null,
      "title": "Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78472"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-5920",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder <= 5.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode_content' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5920"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-18555",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots",
      "cwe": "CWE-79",
      "title": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress <= 2.15.22 - Reflected Cross-Site Scripting via 'icn' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18555"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-84501",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ZooKeeper",
      "cwe": "CWE-117",
      "title": "Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84501"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-78474",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00225,
      "epss_percentile": 0.13376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ni WooCommerce Sales Report",
      "cwe": null,
      "title": "Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78474"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-84829",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00225,
      "epss_percentile": 0.13374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Optimole",
      "cwe": null,
      "title": "Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84829"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-86444",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00225,
      "epss_percentile": 0.13374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": null,
      "title": "LearnPress < 4.4.7 - Reflected XSS via 'skin' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86444"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-86448",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00225,
      "epss_percentile": 0.13376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": null,
      "title": "LearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86448"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-86465",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00223,
      "epss_percentile": 0.13074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Akeyless provider",
      "cwe": "CWE-639",
      "title": "Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86465"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-13407",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal Addons for Elementor",
      "cwe": "CWE-116",
      "title": "Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notification Emails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13407"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-73438",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-617",
      "title": "Security Advisory 0172",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73438"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-89783",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0021,
      "epss_percentile": 0.11445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89783"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-89777",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vfio/pci: clear vdev->msi_perm after freeing it on init failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89777"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-89789",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89789"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-89780",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: qualcomm: rmnet: restore skb->dev on deaggregated frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89780"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-89784",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0021,
      "epss_percentile": 0.11443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89784"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-89793",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: clear VM_MAYWRITE on read-only ublk char device mmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89793"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-76186",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00206,
      "epss_percentile": 0.10941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Keycloak provider",
      "cwe": "CWE-565",
      "title": "Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76186"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-89778",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00205,
      "epss_percentile": 0.10807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "isofs: fix out-of-bounds page array access on empty zisofs block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89778"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-89779",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00205,
      "epss_percentile": 0.10806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: validate ef->size covers the record's name and value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89779"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-89786",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00205,
      "epss_percentile": 0.10809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: fix out-of-bounds read in ext4_read_inline_dir()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89786"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-89781",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89781"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-89782",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: reject restart table growth beyond U16_MAX entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89782"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-11996",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codesupplyco",
      "product": "Advanced Popups",
      "cwe": "CWE-79",
      "title": "Advanced Popups <= 1.2.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11996"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-89776",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00205,
      "epss_percentile": 0.10808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89776"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-89785",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00205,
      "epss_percentile": 0.10808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89785"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-89787",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00205,
      "epss_percentile": 0.10809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89787"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-76556",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00204,
      "epss_percentile": 0.10612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Authenticated SQLi via Export Filter Rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76556"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-76557",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00204,
      "epss_percentile": 0.10612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76557"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-73463",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-362",
      "title": "Security Advisory 0169",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73463"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-84088",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00199,
      "epss_percentile": 0.09927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Xpro Addons — 140+ Widgets for Elementor",
      "cwe": null,
      "title": "Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84088"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-86784",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00199,
      "epss_percentile": 0.09928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Visualizer",
      "cwe": null,
      "title": "Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86784"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-89790",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00198,
      "epss_percentile": 0.09789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: avoid divide by zero in rt6_multipath_rebalance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89790"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-59739",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00197,
      "epss_percentile": 0.09623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ZooKeeper",
      "cwe": "CWE-862",
      "title": "Apache ZooKeeper: Information disclosure via SetWatches reconnect replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59739"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-76558",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00196,
      "epss_percentile": 0.09529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Contributor+ Stored DOM XSS via Custom Field Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76558"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-76187",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00195,
      "epss_percentile": 0.09491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Keycloak provider",
      "cwe": "CWE-287",
      "title": "Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76187"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-76555",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00195,
      "epss_percentile": 0.09482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File Import Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76555"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-82311",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00195,
      "epss_percentile": 0.09491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-613",
      "title": "Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82311"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-86462",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00195,
      "epss_percentile": 0.0949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-613",
      "title": "Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86462"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-19640",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-863",
      "title": "Security Advisory 0170",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19640"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-89774",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: SCO: hold sk properly in sco_conn_ready",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89774"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-82124",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0019,
      "epss_percentile": 0.08907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Schema & Structured Data for WP & AMP",
      "cwe": null,
      "title": "Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82124"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-86445",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0019,
      "epss_percentile": 0.08907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": null,
      "title": "LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86445"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-86447",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0019,
      "epss_percentile": 0.08907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": null,
      "title": "LearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_content_via_ajax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86447"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-86449",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0019,
      "epss_percentile": 0.08907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": null,
      "title": "LearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86449"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-89788",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00189,
      "epss_percentile": 0.08779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix tree connection use-after-free in smb2_tree_connect()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89788"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-89791",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf: Fix use-after-free when perf mmap() revival races with the last munmap()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89791"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-89792",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: prevent out-of-bounds reads in share config responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89792"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-19857",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Formidable Forms",
      "cwe": "CWE-74",
      "title": "Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Custom HTML Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19857"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-89775",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00184,
      "epss_percentile": 0.08235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89775"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-76553",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00182,
      "epss_percentile": 0.08034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76553"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-85349",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00182,
      "epss_percentile": 0.08034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentBoards",
      "cwe": null,
      "title": "FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85349"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-85572",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00182,
      "epss_percentile": 0.08034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": null,
      "title": "Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85572"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-77702",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.0761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": null,
      "title": "Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77702"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-82125",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.0761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Schema & Structured Data for WP & AMP",
      "cwe": null,
      "title": "Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Content Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82125"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-84907",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.0761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": null,
      "title": "Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84907"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-85530",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00178,
      "epss_percentile": 0.07611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GiveWP",
      "cwe": null,
      "title": "GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85530"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-87854",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.0752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Subscriptions for WooCommerce",
      "cwe": null,
      "title": "Subscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87854"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-87896",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.0752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rox Appointment Booking",
      "cwe": null,
      "title": "Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Agent REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87896"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-87907",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00177,
      "epss_percentile": 0.0752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rox Appointment Booking",
      "cwe": null,
      "title": "Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure via Service and Category REST Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87907"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-74926",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MultiVendorX",
      "cwe": null,
      "title": "MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74926"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-76559",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": null,
      "title": "WP Import Export Lite < 3.9.33 - Admin+ SSRF via Import URL Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76559"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-82126",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Schema & Structured Data for WP & AMP",
      "cwe": null,
      "title": "Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content Disclosure via AI Schema Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82126"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-84905",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": null,
      "title": "Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84905"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-85569",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00173,
      "epss_percentile": 0.06966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": null,
      "title": "Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85569"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-87828",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0017,
      "epss_percentile": 0.0666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Seraphinite Accelerator",
      "cwe": null,
      "title": "Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87828"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-89327",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.0646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentBoards",
      "cwe": null,
      "title": "FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89327"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-89328",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentBoards",
      "cwe": null,
      "title": "FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89328"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-86823",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletter",
      "cwe": null,
      "title": "Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86823"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-88910",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00166,
      "epss_percentile": 0.06235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "kboard",
      "cwe": null,
      "title": "KBoard < 6.7 - Unauthenticated Board Media Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88910"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-73435",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-345",
      "title": "Security Advisory 0171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73435"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-87959",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00161,
      "epss_percentile": 0.05673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPBot",
      "cwe": null,
      "title": "WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87959"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-85131",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00145,
      "epss_percentile": 0.04145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPLP Cookie Consent",
      "cwe": null,
      "title": "WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85131"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-84906",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-345",
      "title": "Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84906"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-86466",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00139,
      "epss_percentile": 0.0363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-346",
      "title": "Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86466"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-87860",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00137,
      "epss_percentile": 0.03474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Subscriptions for WooCommerce",
      "cwe": null,
      "title": "Subscriptions for WooCommerce < 2.0.3 - Subscription Cancellation via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87860"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-73450",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.0314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-345",
      "title": "Security Advisory 0161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73450"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-77955",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-345",
      "title": "Possible ZONEMD verification bypass window",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77955"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-81326",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QualitySoft Corporation",
      "product": "QND Premium",
      "cwe": "CWE-321",
      "title": "QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81326"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-85641",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00123,
      "epss_percentile": 0.02325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Formidable Forms",
      "cwe": null,
      "title": "Formidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85641"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-59969",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00122,
      "epss_percentile": 0.0224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ZooKeeper",
      "cwe": "CWE-297",
      "title": "Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59969"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-86443",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fermax Electronica S.A.U.",
      "product": "DuoxMe",
      "cwe": "CWE-312",
      "title": "Cleartext Storage of Sensitive Information Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86443"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-85628",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00077,
      "epss_percentile": 0.00136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fermax Electronica S.A.U.",
      "product": "DuoxMe",
      "cwe": "CWE-319",
      "title": "Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85628"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-20130",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-74",
      "title": "Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20130"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-20192",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-284",
      "title": "Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20192"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-70416",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-502",
      "title": "Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70416"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-76423",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-290",
      "title": "Cisco ISE API Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76423"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-92808",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-306",
      "title": "Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92808"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-20234",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-522",
      "title": "Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20234"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-20307",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-502",
      "title": "Cisco Identity Services Engine Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20307"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-20322",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Nexus Dashboard",
      "cwe": "CWE-284",
      "title": "Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20322"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-20324",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-862",
      "title": "Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20324"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-20325",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Nexus Dashboard",
      "cwe": "CWE-77",
      "title": "Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20325"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-20329",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-703",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20329"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-20330",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-707",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20330"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-20332",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-284",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20332"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2025-59953",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-502",
      "title": "LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59953"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-20242",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-502",
      "title": "Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20242"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-20326",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Nexus Dashboard",
      "cwe": "CWE-306",
      "title": "Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20326"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-89847",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Avoid double completion in async IOCB timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89847"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-89857",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89857"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-89969",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89969"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-89970",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-auth: Synchronize timeout work during SQ teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89970"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-89972",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme: add missing SRCU grace period in error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89972"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-89990",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: lock mutex in ceph_mds_check_access()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89990"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-90012",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: Fix DMA mapping ownership on partial map failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90012"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-90036",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent client use-after-free during blocked-lock reaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90036"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-90037",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent client use-after-free during close_lru reaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90037"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-90038",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Prevent client use-after-free during export state revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90038"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-90042",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: properly decrypt filenames in vmalloc() buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90042"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-90048",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90048"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-91843",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Management",
      "cwe": "CWE-121",
      "title": "Stack overflow in login process to the Security Management and Log Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91843"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-20331",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-693",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20331"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-77411",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-754",
      "title": "RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77411"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-58146",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WNC",
      "product": "T-Mobile 5G Box IDU",
      "cwe": "CWE-78",
      "title": "Unauthorized remote code execution in T-Mobile 5G Box IDU routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58146"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-77405",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-326",
      "title": "RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77405"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-40855",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WNC",
      "product": "T-Mobile 5G Box IDU",
      "cwe": "CWE-78",
      "title": "Command Injection in T-Mobile 5G Box IDU router via ping functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40855"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-58147",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WNC",
      "product": "T-Mobile 5G Box IDU",
      "cwe": "CWE-78",
      "title": "Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58147"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-73172",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73172"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-89082",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP AC Print & Scan",
      "cwe": "CWE-94",
      "title": "HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89082"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-89083",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP AC Print & Scan",
      "cwe": "CWE-94",
      "title": "HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89083"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-89914",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Sign-extend VA for range-based TLBI invalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89914"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-89915",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Remove VM-wide VNCR mapping counter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89915"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-89916",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89916"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-89918",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Correctly handle end of VA space TLBI invalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89918"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-89930",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nVMX: Service local TLB flushes on failed nested VM-Enter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89930"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-90049",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90049"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-91104",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-122",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91104"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-91106",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-122",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91106"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-92717",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cobbr",
      "product": "Covenant",
      "cwe": "CWE-306",
      "title": "Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92717"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-92720",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubero-dev",
      "product": "kubero",
      "cwe": "CWE-306",
      "title": "Kubero through 3.1.1 Unauthenticated Notifications API Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92720"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-92787",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feast-dev",
      "product": "feast",
      "cwe": "CWE-798",
      "title": "Feast through 0.66.0 Authentication Bypass via Unverified Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92787"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-92805",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvdesk",
      "product": "community-skeleton",
      "cwe": "CWE-306",
      "title": "UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92805"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-73456",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-94",
      "title": "Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73456"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-92576",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-918",
      "title": "HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92576"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-92578",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-287",
      "title": "WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92578"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-92749",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chaitin",
      "product": "SafeLine",
      "cwe": "CWE-338",
      "title": "SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92749"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-92785",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Angel-ML",
      "product": "angel",
      "cwe": "CWE-502",
      "title": "Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92785"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-20176",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-77",
      "title": "Cisco Identity Services Engine Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20176"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-20194",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-669",
      "title": "Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20194"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-20211",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-502",
      "title": "Cisco Identity Services Engine Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20211"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-20237",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-20",
      "title": "Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20237"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-20284",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-943",
      "title": "Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20284"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-20305",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-78",
      "title": "Cisco Identity Services Engine Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20305"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-20306",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-78",
      "title": "Cisco Identity Services Engine Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20306"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-20341",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-502",
      "title": "Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20341"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-61594",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-306",
      "title": "djust has an authorization bypass on the WebSocket/SSE mount path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61594"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-75513",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JasperFx",
      "product": "marten",
      "cwe": "CWE-89",
      "title": "Marten: SQL injection in Marten's LINQ provider via unescaped string literals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75513"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-77408",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-190",
      "title": "RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77408"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-89846",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89846"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-90011",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: target: iscsi: Reserve a terminator byte for the login payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90011"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-92395",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/proxy-addr",
      "product": "@fastify/proxy-addr",
      "cwe": "CWE-290",
      "title": "@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92395"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-76420",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-285",
      "title": "Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76420"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-77403",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-770",
      "title": "RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77403"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-77410",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-789",
      "title": "RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77410"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-77412",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-681",
      "title": "RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77412"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-20333",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-697",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Comparison Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20333"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-20336",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-664",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Resource Lifetime Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20336"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-20340",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-502",
      "title": "Cisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20340"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-20344",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-89",
      "title": "Cisco Secure Firewall Management Center Software SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20344"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-20360",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Nexus Dashboard",
      "cwe": "CWE-200",
      "title": "Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20360"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-20361",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Nexus Dashboard",
      "cwe": "CWE-89",
      "title": "Cisco Nexus Dashboard Software Security Hardening Release September 2026 - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20361"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-61599",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-470",
      "title": "djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61599"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-63506",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinacms",
      "product": "tinacms",
      "cwe": "CWE-639",
      "title": "Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63506"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-73173",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-306",
      "title": "Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to invoke critical device-management functions, including network reconfiguration, reboot, reset, and firmware upgrade, by sending crafted requests to TCP port 5058.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73173"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-76409",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Nexus Dashboard",
      "cwe": "CWE-22",
      "title": "Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Limitation of a Pathname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76409"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-82964",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security",
      "cwe": "CWE-281",
      "title": "Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82964"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-84858",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scada-LTS",
      "product": "Scada-LTS",
      "cwe": null,
      "title": "Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84858"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-84860",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scada-LTS",
      "product": "Scada-LTS",
      "cwe": null,
      "title": "Scada-LTS DWR Authorization Bypass - Systemic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84860"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-85731",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oras-project",
      "product": "oras-go",
      "cwe": "CWE-22",
      "title": "oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85731"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-86865",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Asset",
      "cwe": "CWE-89",
      "title": "Tanium addressed a SQL injection vulnerability in Asset.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86865"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-87105",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Threat Response",
      "cwe": "CWE-89",
      "title": "Tanium addressed a SQL injection vulnerability in Threat Response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87105"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-88064",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "backstage",
      "product": "backstage",
      "cwe": "CWE-20",
      "title": "Backstage: Improper input validation in TechDocs MkDocs configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88064"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-89084",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP AC Print & Scan",
      "cwe": "CWE-22",
      "title": "HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89084"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-89804",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/nouveau/dmem: fix mismatched DMA unmap size for large folios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89804"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-89811",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Add TLB flush after MES queue eviction/suspension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89811"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-89844",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89844"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-89849",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89849"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-89860",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Initialize NVMe abort_work once at submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89860"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-89898",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cec: extron-da-hd-4k-plus: add sanity check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89898"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-89907",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: KVM: Validate MSI data before routing it to EIOINTC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89907"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-89908",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89908"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-89913",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89913"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-89928",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89928"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-89929",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89929"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-89932",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nVMX: Always flush vpid02 on first use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89932"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-89951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: fix stale receive device on merged fragments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89951"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-89957",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89957"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-89959",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89959"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-89960",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89960"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-89995",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dma-direct: return struct page from dma_direct_alloc_from_pool()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89995"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-90000",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: rmi: fix OOB access with undersized RMI reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90000"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-90018",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90018"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-90041",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: sony: clean up device list on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90041"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-92122",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-693",
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92122"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-92123",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-693",
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92123"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-92124",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-693",
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92124"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-92125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-94",
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and executing arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92125"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-92137",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Robot Framework Plugin",
      "cwe": "CWE-22",
      "title": "Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content, which can lead to remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92137"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-92566",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datageartech",
      "product": "datagear",
      "cwe": "CWE-918",
      "title": "DataGear through 6.0.0 Unauthenticated SSRF via HTTP Dataset Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92566"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-92729",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-306",
      "title": "SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92729"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-40854",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WNC",
      "product": "T-Mobile 5G Box IDU",
      "cwe": "CWE-290",
      "title": "Session auth bypass via cookie value in T-Mobile 5G Box IDU routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40854"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-47094",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SIMAC",
      "product": "MyPHR",
      "cwe": "CWE-639",
      "title": "SIMAC MyPHR 1.1 IDOR Account Takeover via /api/employes/put/{id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47094"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-73174",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-319",
      "title": "Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73174"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-75516",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-java-client",
      "cwe": "CWE-770",
      "title": "RabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75516"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-77404",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-116",
      "title": "RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77404"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-82410",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pocketbase",
      "product": "pocketbase",
      "cwe": "CWE-248",
      "title": "Pocketbase: Unhandled panic in worker goroutines",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82410"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-86106",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "VeloCloud Edge",
      "cwe": "CWE-306",
      "title": "Security Advisory 0179",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86106"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-86831",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-network-policy-agent",
      "cwe": "CWE-1289",
      "title": "Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86831"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-88817",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Curiosity GmbH",
      "product": "Curiosity Workspace",
      "cwe": "CWE-269",
      "title": "Privilege escalation via legacy access group creation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88817"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-92466",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zlt2000",
      "product": "microservices-platform",
      "cwe": "CWE-862",
      "title": "microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Checking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92466"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-92467",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zlt2000",
      "product": "microservices-platform",
      "cwe": "CWE-620",
      "title": "microservices-platform through 6.0.0 Unverified Password Change via /users/password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92467"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-92577",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "AVideo through 29.0 API get_api_video Broken Access Control via clean_title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92577"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-92580",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-78",
      "title": "AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92580"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-92592",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-1336",
      "title": "Craft CMS before 4.18.6 Remote Code Execution via signed cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92592"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-92593",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-94",
      "title": "Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92593"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-92594",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-200",
      "title": "Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92594"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-92596",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-400",
      "title": "Nodemailer before 9.1.0 Denial of Service via addressparser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92596"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-92599",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "joi",
      "cwe": "CWE-1333",
      "title": "Joi before 17.13.7 and 18.2.6 ReDoS via isoDate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92599"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-92719",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quickwit-oss",
      "product": "quickwit",
      "cwe": "CWE-918",
      "title": "Quickwit through 0.9.0 SSRF via SQS queue_url Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92719"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-92748",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BC-SECURITY",
      "product": "Empire",
      "cwe": "CWE-22",
      "title": "BC Security Empire before 6.7.1 Path Traversal File Upload RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92748"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-92752",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metasfresh",
      "product": "metasfresh",
      "cwe": "CWE-639",
      "title": "metasfresh Unauthorized Access via Document Attachments and Comments Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92752"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-92761",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "retspen",
      "product": "webvirtcloud",
      "cwe": "CWE-862",
      "title": "WebVirtCloud Missing Authorization on Instance Control Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92761"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-92762",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pelican",
      "product": "panel",
      "cwe": "CWE-862",
      "title": "Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92762"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-92780",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "didi",
      "product": "KnowStreaming",
      "cwe": "CWE-862",
      "title": "KnowStreaming through 3.4.1 Missing Authorization on the REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92780"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-92788",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coze-dev",
      "product": "coze-studio",
      "cwe": "CWE-863",
      "title": "Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92788"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-92791",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uber",
      "product": "kraken",
      "cwe": "CWE-22",
      "title": "Uber Kraken through 0.1.29 Path Traversal via tag parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92791"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-92792",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenNHP",
      "product": "opennhp",
      "cwe": "CWE-287",
      "title": "OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92792"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-92794",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSignLabs",
      "product": "OpenSign",
      "cwe": "CWE-862",
      "title": "OpenSign through 2.41.3 Information Disclosure via getDocument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92794"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-92796",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "manticoresoftware",
      "product": "Manticore Search",
      "cwe": "CWE-863",
      "title": "Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92796"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-92801",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chenhg5",
      "product": "cc-connect",
      "cwe": "CWE-863",
      "title": "cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92801"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-92815",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-918",
      "title": "changedetection.io through 0.60.6 SSRF via browser-step Goto URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92815"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-19535",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-352",
      "title": "Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to perform unauthorized state-changing requests on behalf of a logged-in administrator, enabling unauthorized access to privileged management functions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19535"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-20135",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Threat Defense (FTD) Software",
      "cwe": "CWE-415",
      "title": "Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20135"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-20154",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-835",
      "title": "Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software Logging Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20154"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-20249",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-704",
      "title": "Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20249"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-20250",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-772",
      "title": "Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 3100 and 4200 Series DTLS Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20250"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-20295",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-789",
      "title": "Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20295"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-20352",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-119",
      "title": "Cisco Identity Services Engine RADIUS Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20352"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-73163",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73163"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-73164",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73164"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-73165",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73165"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-73166",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-94",
      "title": "Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73166"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-73167",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73167"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-73170",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-94",
      "title": "Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary Lua code on the device via a crafted imported file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73170"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-73171",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-73",
      "title": "Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem by uploading a crafted backup archive through the web management interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73171"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-73176",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73176"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-73177",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-345",
      "title": "Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images through the authenticated web management interface without performing any cryptographic signature or certificate verification. An authenticated administrator-level attacker can install arbitrary modified firmware on the device, enabling full persistent compromise of the platform.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73177"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-91098",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-122",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91098"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-91105",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-122",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91105"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-92716",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shuffle",
      "product": "Shuffle",
      "cwe": "CWE-639",
      "title": "Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92716"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-92763",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rundeck",
      "product": "rundeck",
      "cwe": "CWE-862",
      "title": "Rundeck through 6.2.1 Authorization Bypass via Project Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92763"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-92776",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "requarks",
      "product": "Wiki.js",
      "cwe": "CWE-863",
      "title": "Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92776"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-92782",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chroma-core",
      "product": "chroma",
      "cwe": "CWE-863",
      "title": "Chroma through 1.5.9 Authorization Bypass via Collection Identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92782"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-92793",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GoAdminGroup",
      "product": "go-admin",
      "cwe": "CWE-863",
      "title": "GoAdmin through 1.2.26 Authorization Bypass via Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92793"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-76412",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-264",
      "title": "Cisco Secure Firewall Management Center Software Authenticated Privilege Escalation to Root Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76412"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-86359",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Repository Manager",
      "cwe": "CWE-276",
      "title": "Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86359"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-92397",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruijie",
      "product": "RG-EW3000GX",
      "cwe": "CWE-77",
      "title": "Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92397"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-92398",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruijie",
      "product": "RG-EW3000GX",
      "cwe": "CWE-77",
      "title": "Ruijie RG-EW3000GX user_list_note admin os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92398"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-92786",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lightgbm-org",
      "product": "LightGBM",
      "cwe": "CWE-787",
      "title": "LightGBM through 4.7.0 Out-of-Bounds Write via Crafted Model",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92786"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-92816",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfy-Org",
      "product": "ComfyUI",
      "cwe": "CWE-22",
      "title": "ComfyUI before 0.30.0 Path Traversal via dataset save nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92816"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-20334",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-710",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Coding Standards Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20334"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-40857",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WNC",
      "product": "T-Mobile 5G Box IDU",
      "cwe": "CWE-352",
      "title": "CSRF token bypass in T-Mobile 5G Box IDU routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40857"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-76825",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zopefoundation",
      "product": "RestrictedPython",
      "cwe": "CWE-200",
      "title": "RestrictedPython: Sandbox escape via string.Formatter field resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76825"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-89795",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: Allow per function PCI slots to fix slot reset on s390",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89795"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-89806",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89806"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-89856",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89856"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-89877",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: saa7164: fix cleanup on resource allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89877"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-89885",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: platform: mtk-mdp3: Fix SCP device refcounting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89885"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-89904",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Fix acpi_package_ids[] array overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89904"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-89943",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: loongson: Fix error handling in ACPI property parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89943"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-89980",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: harmony: initialize locks before requesting IRQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89980"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-89992",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpuidle: dt_idle_genpd: kfree() the original name allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89992"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-91102",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-78",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91102"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-20323",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-295",
      "title": "Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20323"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-92597",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-436",
      "title": "Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92597"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-92598",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-436",
      "title": "Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92598"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-63127",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "rust-sdk",
      "cwe": "CWE-345",
      "title": "RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63127"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-71180",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Update Package Framework",
      "cwe": "CWE-252",
      "title": "Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71180"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-76413",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-1259",
      "title": "Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76413"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-77406",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-195",
      "title": "RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77406"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-77409",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-770",
      "title": "RabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77409"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-86107",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "VeloCloud",
      "cwe": "CWE-787",
      "title": "Security Advisory 0180",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86107"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-89028",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-122",
      "title": "MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89028"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-89973",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-tcp: check the data direction of a C2HData PDU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89973"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-92591",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-636",
      "title": "Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92591"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2025-43936",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-287",
      "title": "Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-43936"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-20335",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-682",
      "title": "Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Calculation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20335"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-61591",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-345",
      "title": "djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61591"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-61593",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-352",
      "title": "djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61593"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-63671",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt-content",
      "product": "mdc",
      "cwe": "CWE-79",
      "title": "@nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63671"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-74909",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74909"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-89848",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Quiesce response IRQ before freeing request queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89848"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-89861",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89861"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-89999",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: wacom: validate report length in wacom_intuos_pro2_bt_irq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89999"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-92087",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/auth",
      "product": "@fastify/auth",
      "cwe": "CWE-285",
      "title": "@fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92087"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-85469",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-1357",
      "title": "Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85469"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-89947",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: meson: align gxbb_32k_clk_sel number of parents with actual count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89947"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-89954",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: afs: validate v2 image info bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89954"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-92127",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-94",
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92127"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-92134",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Warnings Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92134"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-92135",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Coverage Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92135"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-92136",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins OWASP Dependency-Check Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92136"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-89911",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Correctly cap TLBI Range to the architural limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89911"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-59974",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stanfordnlp",
      "product": "stanza",
      "cwe": "CWE-22",
      "title": "Stanza: Zip Slip Path Traversal in Model/Resource Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59974"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-63325",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redocly",
      "product": "redocly-cli",
      "cwe": "CWE-94",
      "title": "Redocly CLI: Arbitrary code execution via Arazzo `$faker` expression using `respect`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63325"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-89799",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Disable preemption in bpf_get_stackid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89799"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-89801",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89801"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-89803",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/nouveau: unsubscribe the channel-kill event before the fence context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89803"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-89805",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/pagemap: Fix folio allocation fallback and use-after-put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89805"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-89808",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89808"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-89810",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Fix error path at svm_migrate_copy_to_ram",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89810"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-89814",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: clamp the isolation index for rings outside a partition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89814"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-89815",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/ttm: Drop tt->restore after successful restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89815"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-89819",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: validate plane degamma LUT size for private color prop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89819"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-89823",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm: fix race between partial drm_dev_register() failure and ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89823"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-89825",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/panthor: fix firmware control interface bounds checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89825"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-89829",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89829"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-89832",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix to clear dirty flag on folio in error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89832"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-89836",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix folio_nr_pages() race after put in large folio invalidate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89836"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-89841",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: only redirty pinned folios in redirty_blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89841"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-89854",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix cs84xx use-after-free on host teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89854"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-89870",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: zoran: Avoid freeing a registered video_device twice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89870"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-89873",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-ctrls: validate HEVC EXT SPS RPS counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89873"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-89875",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: ti: vpe: quiesce overflow recovery before freeing streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89875"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-89880",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89880"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-89882",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89882"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-89883",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rc: sunxi-cir: Unregister rc device on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89883"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-89887",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: i2c: ov7740: fix use-after-destroy in remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89887"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-89888",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: i2c: ov02a10: fix endpoint parsing use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89888"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-89890",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: go7007: defer the ALSA v4l2 put until card release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89890"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-89893",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cx23885: cancel NetUP CI work before teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89893"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-89894",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cx231xx: reject geometry changes while the VBI queue is busy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89894"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-89899",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cec: disable delayed work before freeing an interrupted transmit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89899"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-89902",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Avoid preempt count underflow without probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89902"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-89903",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Do not save/restore percpu base register in rethook trampoline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89903"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-89906",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: BPF: Refactor jump offset calculation in tail call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89906"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-89919",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: keyop: use mmu_lock to read gmap->asce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89919"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-89920",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: Fix memory corruption by not reinjecting CK machine checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89920"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-89922",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: Take srcu when importing watchpoint data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89922"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-89938",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89938"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-89940",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: buffer: Tie IIO dma fence lock lifetime to the fence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89940"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-89941",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: buffer: Make IIO DMA fence release RCU-safe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89941"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-89942",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: buffer: Fix potential use-after-free in anonymous buffer release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89942"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-89961",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89961"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-89965",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvdimm/btt: reject an arena whose nfree is below the lane count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89965"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-89967",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/migrate_device: avoid out-of-bounds writes for compound folios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89967"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-89979",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: pcm: Fix race between non-atomic ops and trigger-start",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89979"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-89985",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "memcg: keep folio's objcg same as its node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89985"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-89986",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89986"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-89988",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "kprobes: Protect kprobe_blacklist with RCU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89988"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-89994",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: fsl-edma: tracing: no ptr dereference during log output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89994"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-89997",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm: fix resume-vs-remove race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89997"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-89998",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm: fix race when loading and unloading a table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89998"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-90001",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: bpf: serialize device reference release in struct_ops destroy path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90001"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-90002",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ftrace: Take trace_array reference before accessing its ftrace_ops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90002"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-90003",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex: Prevent rcuwait use-after-free during requeue PI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90003"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-90007",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: pm8001: Use rollback index when freeing MSI-X vectors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90007"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-90008",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90008"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-90009",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: bsg: Fix TOCTOU in io_uring passthrough command setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90009"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-90010",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: bsg: Cap io_uring sense copy to max_response_len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90010"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-90013",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Take trace_array reference when opening options file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90013"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-90014",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracing: Have show_event_filters/triggers files take trace array ref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90014"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-90022",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_midi2: fix use-after-free in string attribute show path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90022"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-90026",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: qcom-pmic: cancel reset_work on stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90026"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-90027",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90027"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-90030",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: dwc3: clear forceRM when issuing EndTransfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90030"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-90032",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: usbtv: keep device alive while ALSA card exists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90032"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-90043",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "zram: fix slot lock bit position on big-endian 64-bit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90043"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-90044",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_fs: Fix Use-After-Free in AIO error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90044"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-90045",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: gadget: ffs: fix mm lifetime handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90045"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-90046",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/page_alloc: don't spin_trylock() in NMI on UP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90046"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-90047",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe: Don't hand out the flat CCS storage as usable VRAM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90047"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-14916",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong",
      "product": "Kong Enteprise Gateway",
      "cwe": "CWE-241",
      "title": "Kong API Gateway Enterprise: JWT Algorithm-Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14916"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-14917",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong",
      "product": "Kong Enterprise Gateway",
      "cwe": "CWE-288",
      "title": "Kong API Gateway Enterprise: SAML Authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14917"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-20342",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-639",
      "title": "Cisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20342"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-61595",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-636",
      "title": "djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61595"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-62997",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kedro-org",
      "product": "kedro-plugins",
      "cwe": "CWE-502",
      "title": "Kedro-Datasets: Remote code execution in experimental `PyTorchDataset` via unsafe `torch.load`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62997"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-85385",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85385"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-86474",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fermax Electronica S.A.U.",
      "product": "DUOX PLUS monitor firmware (VEO Wi-Fi range)",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation in the Firmware Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86474"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-86585",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fermax Electronica S.A.U.",
      "product": "DUOX PLUS monitor firmware (VEO Wi-Fi range)",
      "cwe": "CWE-347",
      "title": "Improper Verification of the Firmware Signature vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86585"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-90025",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: ucsi: displayport: Fix OOB altmode array index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90025"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-92784",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "refinedev",
      "product": "@refinedev/inferencer",
      "cwe": "CWE-94",
      "title": "@refinedev/inferencer through 7.0.0 Code Injection via API Field Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92784"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-76425",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco ISE SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76425"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-92465",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "WP Mega Menu",
      "cwe": "CWE-89",
      "title": "WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92465"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-92616",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "error311",
      "product": "FileRise",
      "cwe": "CWE-613",
      "title": "FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92616"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-92800",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "suitenumerique",
      "product": "Docs",
      "cwe": "CWE-613",
      "title": "Docs before 5.4.1 Stale Collaboration Session After Access Revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92800"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-92812",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decaporg",
      "product": "decap-server",
      "cwe": "CWE-22",
      "title": "decap-server Path Traversal via Sibling Directory Prefix Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92812"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-18212",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-401",
      "title": "Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18212"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-19666",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-416",
      "title": "Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19666"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-19667",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-197",
      "title": "Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19667"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-20247",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco Identity Services Engine Unauthenticated SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20247"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-20343",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-306",
      "title": "Cisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20343"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-46352",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-833",
      "title": "Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46352"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-63126",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "square",
      "product": "wire",
      "cwe": "CWE-190",
      "title": "Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63126"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-63128",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "rust-sdk",
      "cwe": "CWE-400",
      "title": "RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63128"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-76163",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-617",
      "title": "named aborts on a TKEY query when the user configuration has no global options statement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76163"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-77692",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-476",
      "title": "Unauthenticated remote crash of named via a single DoH SIG(0) request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77692"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-79651",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-400",
      "title": "Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79651"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-80274",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-617",
      "title": "Validating resolver can abort while caching a mismatched NOQNAME proof",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80274"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-81563",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-401",
      "title": "SVCB AliasMode additional-data error leaks qpcache references",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81563"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-81736",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-1050",
      "title": "Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81736"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-81875",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-20",
      "title": "HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81875"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-81876",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-20",
      "title": "HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81876"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-82399",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coredns",
      "product": "coredns",
      "cwe": "CWE-770",
      "title": "CoreDNS: Unauthenticated memory exhaustion in custom transports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82399"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-84997",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reactphp",
      "product": "http",
      "cwe": "CWE-835",
      "title": "react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84997"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-85756",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sshnet",
      "product": "SSH.NET",
      "cwe": "CWE-78",
      "title": "SSH.NET: ScpClient allows server-side RCE via default SCP path handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85756"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-86003",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coredns",
      "product": "coredns",
      "cwe": "CWE-441",
      "title": "CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86003"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-86043",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zalando",
      "product": "skipper",
      "cwe": "CWE-863",
      "title": "Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix CVE-2026-50197)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86043"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-89863",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89863"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-89897",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cec: Serialize exclusive follower delivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89897"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-89968",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-tcp: reject unsolicited H2CData PDUs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89968"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-89971",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme: skip the zoned limits update if the zone info query failed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89971"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-89974",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89974"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-92128",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-494",
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92128"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-92129",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-693",
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92129"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-92625",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Control iD",
      "product": "iDSecure",
      "cwe": "CWE-306",
      "title": "Control iD iDSecure Unauthenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92625"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-92626",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Control iD",
      "product": "iDSecure",
      "cwe": "CWE-476",
      "title": "Control iD iDSecure Unauthenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92626"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-20222",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-401",
      "title": "Cisco Secure Adaptive Security Appliance Software and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20222"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-42784",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Confidential Compute Attestation",
      "cwe": "CWE-347",
      "title": "Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42784"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-61590",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-306",
      "title": "djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61590"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-61592",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-384",
      "title": "djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61592"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-71179",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Update Package Framework",
      "cwe": "CWE-78",
      "title": "Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71179"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-85386",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85386"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-89910",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89910"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-17526",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17526"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-76424",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-23",
      "title": "Cisco ISE Arbitrary File Access Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76424"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-87024",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Asset",
      "cwe": "CWE-89",
      "title": "Tanium addressed a SQL injection vulnerability in Asset.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87024"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-87976",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi Registry",
      "cwe": "CWE-22",
      "title": "Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87976"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-92469",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zlt2000",
      "product": "microservices-platform",
      "cwe": "CWE-639",
      "title": "microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92469"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-92604",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StamusNetworks",
      "product": "scirius",
      "cwe": "CWE-22",
      "title": "Scirius through 3.8.0 Arbitrary File Write via PCAP Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92604"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-92751",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yahoo",
      "product": "CMAK",
      "cwe": "CWE-352",
      "title": "CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92751"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-92779",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BuilderIO",
      "product": "@builder.io/sdk-react",
      "cwe": "CWE-1321",
      "title": "Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92779"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-92783",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yeti-platform",
      "product": "yeti",
      "cwe": "CWE-862",
      "title": "Yeti through 2.11.0 Missing Authorization on RBAC Relationship Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92783"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-92806",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpList",
      "product": "phpList",
      "cwe": "CWE-352",
      "title": "phpList before 3.6.17 Cross-Site Request Forgery via massremove.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92806"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-20300",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco Identity Services Engine SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20300"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-40856",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WNC",
      "product": "T-Mobile 5G Box IDU",
      "cwe": "CWE-306",
      "title": "Config disclosure in T-Mobile 5G Box IDU routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40856"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-61596",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-639",
      "title": "djust has broken object-level access control (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61596"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-61598",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-915",
      "title": "Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61598"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-73175",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-400",
      "title": "Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73175"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-73462",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-125",
      "title": "On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the I",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73462"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-89034",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TCH",
      "product": "QRing",
      "cwe": "CWE-306",
      "title": "TCH QRing R20_B006 Unauthenticated BLE Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89034"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-89818",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89818"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-89826",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/panthor: harden firmware build-info bounds checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89826"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-89838",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: limit recovery filename logging to stored length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89838"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-89840",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: validate MOVE_RANGE destination size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89840"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-89912",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89912"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-89927",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89927"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-90016",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90016"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-90017",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90017"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-92417",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-404",
      "title": "Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92417"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-92456",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92456"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-92457",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92457"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-92459",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92459"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-92460",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92460"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-92462",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92462"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-92463",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92463"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-92468",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zlt2000",
      "product": "microservices-platform",
      "cwe": "CWE-639",
      "title": "microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92468"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-92567",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckCloud",
      "product": "tduck-survey-form",
      "cwe": "CWE-639",
      "title": "TDuck survey form through 5.0 Unauthorized Data Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92567"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-92570",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yogeshojha",
      "product": "rengine",
      "cwe": "CWE-862",
      "title": "reNgine through 2.2.0 Unauthorized Configuration File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92570"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-92582",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "AVideo through 29.0 Broken Access Control via videoAddNew.json.php CSRF Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92582"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-92600",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylefeng",
      "product": "Guns",
      "cwe": "CWE-862",
      "title": "Guns through 8.3.5 Information Disclosure via Missing Permission Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92600"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-92601",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylefeng",
      "product": "Guns",
      "cwe": "CWE-862",
      "title": "Guns through 8.3.5 Improper Access Control via SysNoticeController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92601"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-92602",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckCloud",
      "product": "tduck-survey-form",
      "cwe": "CWE-918",
      "title": "TDuck survey form through 5.3 Server-Side Request Forgery via Unvalidated Webhook URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92602"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-92603",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "continew-org",
      "product": "continew-admin",
      "cwe": "CWE-639",
      "title": "ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92603"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-92605",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-639",
      "title": "IRIS through 2.4.29 Unauthorized Comment Access via Object ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92605"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-92750",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harness",
      "product": "harness",
      "cwe": "CWE-862",
      "title": "Harness through 3.3.0 Missing Access Control via infraproviders endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92750"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-92753",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Patrowl",
      "product": "PatrowlManager",
      "cwe": "CWE-862",
      "title": "PatrowlManager through 1.8.4 Authorization Bypass via Events API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92753"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-92759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SecObserve",
      "product": "SecObserve",
      "cwe": "CWE-522",
      "title": "SecObserve before 1.59.1 Information Disclosure via API Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92759"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-92760",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shlinkio",
      "product": "shlink",
      "cwe": "CWE-863",
      "title": "Shlink through 5.1.6 Mercure Token Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92760"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-92765",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "archerysec",
      "product": "archerysec",
      "cwe": "CWE-639",
      "title": "ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92765"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-92770",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goharbor",
      "product": "harbor",
      "cwe": "CWE-200",
      "title": "Harbor through 2.15.2 Scanner Credential Disclosure via Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92770"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-92771",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-863",
      "title": "Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92771"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-92772",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "leantime",
      "cwe": "CWE-862",
      "title": "Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92772"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-92773",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "triggerdotdev",
      "product": "trigger.dev",
      "cwe": "CWE-639",
      "title": "Trigger.dev before 4.6.0 GitHub App Installation Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92773"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-92775",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "requarks",
      "product": "Wiki.js",
      "cwe": "CWE-918",
      "title": "Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92775"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-92789",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Graylog2",
      "product": "graylog2-server",
      "cwe": "CWE-918",
      "title": "Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92789"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-92795",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coze-dev",
      "product": "coze-studio",
      "cwe": "CWE-918",
      "title": "Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92795"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-92804",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NangoHQ",
      "product": "Nango",
      "cwe": "CWE-918",
      "title": "Nango through 0.70.4 Server-Side Request Forgery via Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92804"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-92811",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browserless",
      "product": "browserless",
      "cwe": "CWE-200",
      "title": "browserless 1.44.0 through 2.56.7 File Protocol Restriction Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92811"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-68904",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "node-opcua",
      "product": "node-opcua",
      "cwe": "CWE-400",
      "title": "node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68904"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-77407",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "amqp091-go",
      "cwe": "CWE-316",
      "title": "RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77407"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-91097",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-787",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91097"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-92718",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectdiscovery",
      "product": "nuclei",
      "cwe": "CWE-347",
      "title": "Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92718"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-92362",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-400",
      "title": "ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92362"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-92401",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChangeWeDer",
      "product": "crm",
      "cwe": "CWE-287",
      "title": "ChangeWeDer crm improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92401"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-92565",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lukevella",
      "product": "rallly",
      "cwe": "CWE-359",
      "title": "Rallly before 4.15.0 Information Disclosure via polls.get",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92565"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-92583",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-307",
      "title": "AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92583"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-92790",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "higress-group",
      "product": "higress",
      "cwe": "CWE-703",
      "title": "Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92790"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-92803",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LibreTranslate",
      "product": "LibreTranslate",
      "cwe": "CWE-862",
      "title": "LibreTranslate through 1.9.6 Missing Access Check on the download_file Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92803"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-92813",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metabase",
      "product": "Metabase",
      "cwe": "CWE-918",
      "title": "Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92813"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-20248",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-195",
      "title": "Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20248"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-64684",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "rust-sdk",
      "cwe": "CWE-200",
      "title": "RMCP: Custom HTTP headers leak to cross-origin redirect targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64684"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-77401",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zopefoundation",
      "product": "AccessControl",
      "cwe": "CWE-693",
      "title": "Zope AccessControl: Information disclosure through Python string `format` and `format_map` functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77401"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-91100",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-78",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91100"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-92140",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Gitee Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92140"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-26947",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ECS",
      "cwe": "CWE-269",
      "title": "Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26947"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-92615",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-413",
      "title": "Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92615"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-19033",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-349",
      "title": "Unauthenticated IXFR deltas are applied to the live zone before TSIG verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19033"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-20283",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-78",
      "title": "Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20283"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-20287",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-269",
      "title": "Cisco Identity Services Engine Hardening Release - Improper Privlege Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20287"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-57173",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-770",
      "title": "vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57173"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-61588",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-200",
      "title": "djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61588"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-62949",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ronf",
      "product": "asyncssh",
      "cwe": "CWE-835",
      "title": "AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62949"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-69147",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-400",
      "title": "vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69147"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-76438",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco BroadWorks",
      "cwe": "CWE-863",
      "title": "Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76438"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-84859",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scada-LTS",
      "product": "Scada-LTS",
      "cwe": null,
      "title": "Scada-LTS Authenticated Blind SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84859"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-84993",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mikro-orm",
      "product": "mikro-orm",
      "cwe": "CWE-89",
      "title": "MikroORM: SQL injection via unvalidated order direction in orderBy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84993"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-86358",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Update Package Framework",
      "cwe": "CWE-121",
      "title": "Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86358"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-87076",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Discover",
      "cwe": "CWE-200",
      "title": "Tanium addressed an information disclosure vulnerability in Discover.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87076"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-87116",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Threat Response",
      "cwe": "CWE-918",
      "title": "Tanium addressed a server-side request forgery vulnerability in Threat Response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87116"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-92139",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Bitbucket Push and Pull Request Plugin",
      "cwe": "CWE-918",
      "title": "Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92139"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-18120",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Missing Authorization in legacy Express entries search endpoint allows disclosure of Express entry data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18120"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-56719",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-125",
      "title": "MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56719"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-61589",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-348",
      "title": "djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61589"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-73169",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "EKI-1242IEIMS",
      "cwe": "CWE-79",
      "title": "Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to store malicious script content that executes in the browser of any administrator who later opens an affected management page.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73169"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-77360",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "middleapi",
      "product": "orpc",
      "cwe": "CWE-113",
      "title": "oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77360"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-81871",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-go",
      "cwe": "CWE-295",
      "title": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81871"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-81872",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-go",
      "cwe": "CWE-400",
      "title": "OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81872"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-87113",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Threat Response",
      "cwe": "CWE-639",
      "title": "Tanium addressed an improper access controls vulnerability in Threat Response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87113"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-20309",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-79",
      "title": "Cisco Identity Services Engine Cross-Site Scripting Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20309"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-59944",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "composer",
      "product": "composer",
      "cwe": "CWE-22",
      "title": "Composer: CVE-2026-59946 fix bypass via symlinked package bin path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59944"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-88976",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "udecode",
      "product": "plate",
      "cwe": "CWE-79",
      "title": "@platejs/core HTML deserialization can trigger browser behavior during parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88976"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-73457",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-532",
      "title": "Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73457"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-77190",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-20",
      "title": "Security Advisory 0177",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77190"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-92595",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodemailer",
      "product": "nodemailer",
      "cwe": "CWE-73",
      "title": "Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92595"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-19662",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-416",
      "title": "qpcache NOQNAME proof use-after-free crashes recursive resolver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19662"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-19941",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-345",
      "title": "checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19941"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-77119",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-346",
      "title": "NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77119"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-82561",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-862",
      "title": "Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82561"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-92588",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 1.123.76 Improper Authorization via Source Control Push",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92588"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-20120",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-284",
      "title": "Cisco FTD ACL bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20120"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-20290",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Threat Defense (FTD) Software",
      "cwe": "CWE-805",
      "title": "Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20290"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-78301",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-349",
      "title": "Out-of-zone database nodes can become authoritative zone cuts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78301"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-76104",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ObjectScale",
      "cwe": "CWE-732",
      "title": "Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76104"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-92366",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Matrimonial System",
      "cwe": "CWE-74",
      "title": "code-projects Matrimonial System Regular Search search.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92366"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-92380",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "WuzhiCMS",
      "cwe": "CWE-918",
      "title": "WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92380"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-92399",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92399"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-92405",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory and Monitoring System",
      "cwe": "CWE-74",
      "title": "SourceCodester Inventory and Monitoring System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92405"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-92406",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory and Monitoring System",
      "cwe": "CWE-74",
      "title": "SourceCodester Inventory and Monitoring System btn_functions.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92406"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-84397",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84397"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-92132",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Gradle Plugin",
      "cwe": "CWE-74",
      "title": "Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the global configuration by having Jenkins connect to an attacker-specified URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92132"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-92133",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins GitLab Plugin",
      "cwe": "CWE-522",
      "title": "Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92133"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-19607",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-287",
      "title": "Keycloak-services: keycloak-services: broker-originated username collision causes account lockout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19607"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-19668",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-407",
      "title": "Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19668"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-20121",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
      "cwe": "CWE-284",
      "title": "CIsco FTD Bypass Access List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20121"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-59823",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-918",
      "title": "LiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59823"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-61709",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openfga",
      "product": "openfga",
      "cwe": "CWE-281",
      "title": "OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61709"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-73443",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-294",
      "title": "On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indef",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73443"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-75029",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-405",
      "title": "Message parser retains every identical singleton RDATA, enabling wire-to-work amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75029"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-76433",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-22",
      "title": "Cisco Identity Services Engine Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76433"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-76439",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-306",
      "title": "Cisco Identity Services Engine Event Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76439"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-76444",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-306",
      "title": "Cisco Identity Services Engine Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76444"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-76447",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-306",
      "title": "Cisco Identity Services Engine Certificate Reload Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76447"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-81176",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "devalue",
      "cwe": "CWE-770",
      "title": "Svelte devalue: DoS via malformed input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81176"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-85104",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sooma",
      "product": "Sooma tDCS Home Therapy",
      "cwe": "CWE-924",
      "title": "Brain stimulation parameters can be modified via Bluetooth in Sooma",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85104"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-87028",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87028"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-89029",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adenion",
      "product": "Blog2Social",
      "cwe": "CWE-639",
      "title": "Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89029"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-89030",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adenion",
      "product": "Blog2Social",
      "cwe": "CWE-862",
      "title": "Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89030"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-89031",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adenion",
      "product": "Blog2Social",
      "cwe": "CWE-639",
      "title": "Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89031"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-92356",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2ui-project",
      "product": "a2ui",
      "cwe": "CWE-400",
      "title": "a2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92356"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-92357",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a2ui-project",
      "product": "a2ui",
      "cwe": "CWE-200",
      "title": "a2ui-project a2ui Model Processor model-processor.ts information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92357"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-92360",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-345",
      "title": "ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92360"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-92361",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-400",
      "title": "ag-ui-protocol ag-ui SSE Client client.go resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92361"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-92363",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-400",
      "title": "ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92363"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-92365",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-404",
      "title": "vllm-project vllm thinking_budget_state.py algorithmic complexity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92365"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-92402",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChangeWeDer",
      "product": "crm",
      "cwe": "CWE-862",
      "title": "ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92402"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-92416",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-617",
      "title": "Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92416"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-92455",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92455"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-92458",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92458"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-92461",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guchengwuyue",
      "product": "yshop-crm",
      "cwe": "CWE-862",
      "title": "yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92461"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-92568",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlrun",
      "product": "mlrun",
      "cwe": "CWE-918",
      "title": "MLRun through 1.11.0 Server-Side Request Forgery via Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92568"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-92569",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opengoofy",
      "product": "hippo4j",
      "cwe": "CWE-918",
      "title": "Hippo4j through 1.5.0 SSRF via clientAddress Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92569"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-92579",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-289",
      "title": "AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92579"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-92581",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-20",
      "title": "AVideo through 29.0 Like Counter Desynchronization via Array Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92581"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-92584",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92584"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-92585",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "AVideo through 29.0 Missing Authorization Check via API Like Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92585"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-92586",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "AVideo through 29.0 Missing Authorization via comment API endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92586"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-92587",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-426",
      "title": "n8n before 1.123.76 Sandbox Escape via Git Relative URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92587"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-92589",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92589"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-92754",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Patrowl",
      "product": "PatrowlManager",
      "cwe": "CWE-862",
      "title": "PatrowlManager through 1.8.4 Improper Access Control via users API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92754"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-92764",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opencve",
      "product": "opencve",
      "cwe": "CWE-863",
      "title": "OpenCVE before 3.1.0 Organization API Ignores Token Scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92764"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-92774",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "requarks",
      "product": "Wiki.js",
      "cwe": "CWE-863",
      "title": "Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92774"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-92778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yahoo",
      "product": "CMAK",
      "cwe": "CWE-693",
      "title": "CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92778"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-92781",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BuilderIO",
      "product": "@builder.io/sdk-react",
      "cwe": "CWE-1321",
      "title": "Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92781"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-92802",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kanbn",
      "product": "kan",
      "cwe": "CWE-862",
      "title": "kan through 0.6.0 Authorization Bypass via GitHub Project Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92802"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-92809",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrestaShop",
      "product": "psgdpr",
      "cwe": "CWE-639",
      "title": "PrestaShop psgdpr through 1.4.3 GDPR Log Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92809"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-92810",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrestaShop",
      "product": "blockwishlist",
      "cwe": "CWE-639",
      "title": "PrestaShop blockwishlist through 3.0.2 Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92810"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-61597",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djust-org",
      "product": "djust",
      "cwe": "CWE-79",
      "title": "djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61597"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-81869",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-go",
      "cwe": "CWE-176",
      "title": "OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81869"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-91099",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-61",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91099"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-91101",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-129",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91101"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-91103",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Linux Imaging and Printing Software (HPLIP)",
      "cwe": "CWE-191",
      "title": "HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91103"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-92590",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92590"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-20072",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-863",
      "title": "ISE information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20072"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-20235",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco Identity Services Engine Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20235"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-20282",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-641",
      "title": "Cisco Identity Services Engine Authenticated Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20282"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-76426",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco ISE REST API SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76426"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-76427",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-611",
      "title": "Cisco ISE XML External Entity Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76427"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-76428",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco ISE Profiler SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76428"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-76431",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-22",
      "title": "Cisco Identity Services Engine Arbitrary File Deletion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76431"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-76432",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-22",
      "title": "Cisco Identity Services Engine Arbitrary File Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76432"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-76434",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-22",
      "title": "Cisco Identity Services Engine Arbitrary File Read Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76434"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-76446",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-611",
      "title": "Cisco Identity Services Engine External Entity Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76446"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-76448",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco Identity Services Engine SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76448"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-76449",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-89",
      "title": "Cisco Identity Services Engine SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76449"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-76450",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-564",
      "title": "Cisco Identity Services Engine SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76450"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-76451",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-564",
      "title": "Cisco Identity Services Engine Certificate Management SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76451"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-20350",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco ThousandEyes Enterprise Agent",
      "cwe": "CWE-78",
      "title": "Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20350"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-75025",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-346",
      "title": "Mattermost Desktop local network access from server-rendered content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75025"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-85732",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oras-project",
      "product": "oras-go",
      "cwe": "CWE-918",
      "title": "oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85732"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-76151",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "qt",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76151"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-92627",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-416",
      "title": "Heap Use-After-Free in H5T__conv_f_f",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92627"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2025-36591",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Elastic Cloud Storage (ECS)",
      "cwe": "CWE-327",
      "title": "Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36591"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-63225",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redocly",
      "product": "redocly-cli",
      "cwe": "CWE-22",
      "title": "Redocly CLI: Path traversal when using `split` command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63225"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-20285",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-285",
      "title": "Cisco Identity Services Engine Authorization Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20285"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-20286",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-285",
      "title": "Cisco Identity Services Engine Authorization Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20286"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-92141",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Keycloak Authentication Plugin",
      "cwe": "CWE-601",
      "title": "Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92141"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-92131",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Groovy Libraries Plugin",
      "cwe": "CWE-22",
      "title": "Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal vulnerability, allowing attackers able to configure Pipelines to read files in a resources directory and to delete files in a test directory on the Jenkins controller file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92131"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-92138",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Bitbucket Server Integration Plugin",
      "cwe": "CWE-345",
      "title": "The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92138"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-20071",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-290",
      "title": "ISE 802.1x Session Hijack Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20071"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-87026",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Threat Response",
      "cwe": "CWE-862",
      "title": "Tanium addressed an improper access controls vulnerability in Threat Response.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87026"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-69200",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "node-opcua",
      "product": "node-opcua",
      "cwe": "CWE-1321",
      "title": "node-opcua: Prototype Pollution via internal `fieldsToJson()` implementation (Related to CVE-2024-57086)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69200"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-86071",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "junrar",
      "product": "junrar",
      "cwe": "CWE-22",
      "title": "Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86071"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-92130",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Multibranch Plugin",
      "cwe": "CWE-863",
      "title": "Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92130"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-71181",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Update Package Framework",
      "cwe": "CWE-59",
      "title": "Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71181"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-71182",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Update Package Framework",
      "cwe": "CWE-59",
      "title": "Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71182"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-86089",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-862",
      "title": "Apache NiFi: Missing Process Group Authorization for Connector Migration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86089"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-92359",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ag-ui-protocol",
      "product": "ag-ui",
      "cwe": "CWE-346",
      "title": "ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92359"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-92814",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-79",
      "title": "changedetection.io through 0.60.6 Cross-Site Scripting via watch_title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92814"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-73442",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-532",
      "title": "On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73442"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-87031",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87031"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-92364",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92364"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-92383",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PbootCMS",
      "cwe": "CWE-352",
      "title": "PbootCMS User Management UserController.php mod cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92383"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-92413",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Artifex",
      "product": "MuPDF",
      "cwe": "CWE-404",
      "title": "Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92413"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-92526",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92526"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-92527",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "chatwoot",
      "cwe": "CWE-918",
      "title": "chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92527"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-81870",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-go",
      "cwe": "CWE-200",
      "title": "OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81870"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-85387",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-613",
      "title": "Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85387"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-92381",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PbootCMS",
      "cwe": "CWE-79",
      "title": "PbootCMS Template Rendering ContentController.php decode_string cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92381"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-92418",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChangeWeDer",
      "product": "crm",
      "cwe": "CWE-79",
      "title": "ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92418"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-92385",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Food Ordering System",
      "cwe": "CWE-79",
      "title": "SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92385"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-92472",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92472"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-92473",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC BIFS commands.c gf_sg_command_del use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92473"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-92474",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92474"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-92475",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC downloader.c wait_for_header_and_parse out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92475"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-81866",
      "cvss_base": 0.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-862",
      "title": "Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81866"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2025-56563",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to make arbitrary HTTP and HTTPS requests from the server to internal networks or cloud metadata services, potentially obtaining sensitive information or pivoting to further attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-56563"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2025-56565",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email notification credentials and administrative passwords. An attacker with physical access to the device can extract these credentials from an SPI flash dump, leading to device compromise, infiltration of the connected network and unauthorised access to dependent third-party services.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-56565"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2025-56566",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-56566"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-38999",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38999"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-51990",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51990"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-65388",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "containerization",
      "cwe": null,
      "title": "A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65388"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-68536",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MyFaces",
      "cwe": "CWE-918",
      "title": "Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68536"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-70469",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-409",
      "title": "Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70469"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-76646",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MyFaces",
      "cwe": "CWE-400",
      "title": "Apache MyFaces: Denial of Service via Unbounded Request Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76646"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-79298",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79298"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-88592",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filter is not the same parameter the controller actually fetches: the filter validates the first non-empty parameter in a fixed priority order, while the controller only reads and fetches urlPath. By supplying both urlPath=<real target> and url=<whitelisted decoy address> in the same request, the decoy passes validation while the unvalidated real target is fetched server-side — and the response body is echoed back to the attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88592"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-88593",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88593"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-89794",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: zero pipe read compound padding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89794"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-89796",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/damon/core: avoid infinite kdamond_merge_regions() internal loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89796"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-89797",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: ab8500_fg: fix use-after-free on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89797"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-89798",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rpcrdma: arm rn_done before publishing the notification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89798"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-89800",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89800"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-89802",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89802"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-89807",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89807"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-89809",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89809"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-89812",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: force complete the MES ring fences on reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89812"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-89813",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: force complete the KIQ ring fences on reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89813"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-89816",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89816"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-89817",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/gud: NUL-terminate TV mode names read from the device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89817"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-89820",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: fix dc_lock leak on GPU reset error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89820"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-89821",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: avoid divide-by-zero in __is_lut_linear()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89821"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-89822",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915: Guard against NULL driver_data in i915_pci_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89822"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-89824",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/panel-edp: fix i2c adapter leak on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89824"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-89827",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: avoid force-completing uninitialized UVD rings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89827"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-89828",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89828"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-89830",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix valid block count leak on data block allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89830"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-89831",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: protect critical_task_priority updates with s_umount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89831"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-89833",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89833"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-89834",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix to migrate all curseg types during free_segment_range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89834"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-89835",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: avoid NULL checkpoint thread access in sysfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89835"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-89837",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix dentry folio leak in find_in_level",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89837"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-89839",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89839"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-89842",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89842"
    },
    {
      "rank": 778,
      "cve_id": "CVE-2026-89843",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89843"
    },
    {
      "rank": 779,
      "cve_id": "CVE-2026-89845",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89845"
    },
    {
      "rank": 780,
      "cve_id": "CVE-2026-89850",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Don't query firmware state while chip is down",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89850"
    },
    {
      "rank": 781,
      "cve_id": "CVE-2026-89851",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix FCE trace enable parsing in debugfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89851"
    },
    {
      "rank": 782,
      "cve_id": "CVE-2026-89852",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89852"
    },
    {
      "rank": 783,
      "cve_id": "CVE-2026-89853",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89853"
    },
    {
      "rank": 784,
      "cve_id": "CVE-2026-89855",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Serialize flash version read in reset handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89855"
    },
    {
      "rank": 785,
      "cve_id": "CVE-2026-89858",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89858"
    },
    {
      "rank": 786,
      "cve_id": "CVE-2026-89859",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89859"
    },
    {
      "rank": 787,
      "cve_id": "CVE-2026-89862",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix BSG job leak on validate flash image error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89862"
    },
    {
      "rank": 788,
      "cve_id": "CVE-2026-89864",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Bound i2c->length in I2C bsg handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89864"
    },
    {
      "rank": 789,
      "cve_id": "CVE-2026-89865",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89865"
    },
    {
      "rank": 790,
      "cve_id": "CVE-2026-89866",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: chips-media: wave5: Resume device before setting EOS flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89866"
    },
    {
      "rank": 791,
      "cve_id": "CVE-2026-89867",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89867"
    },
    {
      "rank": 792,
      "cve_id": "CVE-2026-89868",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: chips-media: wave5: Add timeout while stop_streaming",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89868"
    },
    {
      "rank": 793,
      "cve_id": "CVE-2026-89869",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: qcom: iris: use disable_irq() during power-off",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89869"
    },
    {
      "rank": 794,
      "cve_id": "CVE-2026-89871",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89871"
    },
    {
      "rank": 795,
      "cve_id": "CVE-2026-89872",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89872"
    },
    {
      "rank": 796,
      "cve_id": "CVE-2026-89874",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-async: avoid deleting unlinked ASC entry on link error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89874"
    },
    {
      "rank": 797,
      "cve_id": "CVE-2026-89876",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: tda18250: fix possible integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89876"
    },
    {
      "rank": 798,
      "cve_id": "CVE-2026-89878",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: s2255: check firmware size before reading trailing marker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89878"
    },
    {
      "rank": 799,
      "cve_id": "CVE-2026-89879",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: s2255: bound JPEG frame size before copying into the buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89879"
    },
    {
      "rank": 800,
      "cve_id": "CVE-2026-89881",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89881"
    },
    {
      "rank": 801,
      "cve_id": "CVE-2026-89884",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89884"
    },
    {
      "rank": 802,
      "cve_id": "CVE-2026-89886",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: intel/ipu6: fix async notifier cleanup leak on parse error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89886"
    },
    {
      "rank": 803,
      "cve_id": "CVE-2026-89889",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: i2c: imx415: Release runtime PM reference on VBLANK error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89889"
    },
    {
      "rank": 804,
      "cve_id": "CVE-2026-89891",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: em28xx: fix use-after-free of dev_next->devlist on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89891"
    },
    {
      "rank": 805,
      "cve_id": "CVE-2026-89892",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: em28xx: defer audio-only extension registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89892"
    },
    {
      "rank": 806,
      "cve_id": "CVE-2026-89895",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cobalt: Avoid freeing ALSA private data twice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89895"
    },
    {
      "rank": 807,
      "cve_id": "CVE-2026-89896",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cedrus: fix memory leak in cedrus_init_ctrls()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89896"
    },
    {
      "rank": 808,
      "cve_id": "CVE-2026-89900",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: cec: core: Fix kmemleak due to missed rc_free_device() call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89900"
    },
    {
      "rank": 809,
      "cve_id": "CVE-2026-89901",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89901"
    },
    {
      "rank": 810,
      "cve_id": "CVE-2026-89905",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: BPF: Move arena register slot below TCC context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89905"
    },
    {
      "rank": 811,
      "cve_id": "CVE-2026-89909",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: KVM: Free init resources if kvm_init() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89909"
    },
    {
      "rank": 812,
      "cve_id": "CVE-2026-89917",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89917"
    },
    {
      "rank": 813,
      "cve_id": "CVE-2026-89921",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: Zero initialize data structures for inject_pfault_token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89921"
    },
    {
      "rank": 814,
      "cve_id": "CVE-2026-89923",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: Free guest debug data on vcpu destroy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89923"
    },
    {
      "rank": 815,
      "cve_id": "CVE-2026-89924",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: Fix old_data leak in guest debug error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89924"
    },
    {
      "rank": 816,
      "cve_id": "CVE-2026-89925",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: Fix memory leak in guest debug handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89925"
    },
    {
      "rank": 817,
      "cve_id": "CVE-2026-89926",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: s390: Fix length check __import_wp_info()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89926"
    },
    {
      "rank": 818,
      "cve_id": "CVE-2026-89931",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89931"
    },
    {
      "rank": 819,
      "cve_id": "CVE-2026-89933",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: pressure: dps310: fix NULL pointer dereference on ACPI probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89933"
    },
    {
      "rank": 820,
      "cve_id": "CVE-2026-89934",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: light: ltrf216a: fix runtime PM reference leak in error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89934"
    },
    {
      "rank": 821,
      "cve_id": "CVE-2026-89935",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: light: apds9306: fix PM reference leak in apds9306_read_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89935"
    },
    {
      "rank": 822,
      "cve_id": "CVE-2026-89936",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: dac: m62332: Fix regulator reference count imbalance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89936"
    },
    {
      "rank": 823,
      "cve_id": "CVE-2026-89937",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: chemical: sgp30: Handle IAQ thread creation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89937"
    },
    {
      "rank": 824,
      "cve_id": "CVE-2026-89939",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89939"
    },
    {
      "rank": 825,
      "cve_id": "CVE-2026-89944",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: hdac_hda: Fix hlink refcount leak on component registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89944"
    },
    {
      "rank": 826,
      "cve_id": "CVE-2026-89945",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: cs35l34: drain threaded IRQ before runtime suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89945"
    },
    {
      "rank": 827,
      "cve_id": "CVE-2026-89946",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: cs35l33: drain threaded IRQ before runtime suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89946"
    },
    {
      "rank": 828,
      "cve_id": "CVE-2026-89948",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: bla: fix freeing of claims on meshif deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89948"
    },
    {
      "rank": 829,
      "cve_id": "CVE-2026-89949",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: dat: avoid unaligned fault in IP extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89949"
    },
    {
      "rank": 830,
      "cve_id": "CVE-2026-89950",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: mcast: linearize skbuff for packet generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89950"
    },
    {
      "rank": 831,
      "cve_id": "CVE-2026-89952",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: rawnand: validate ONFI extended parameter page sections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89952"
    },
    {
      "rank": 832,
      "cve_id": "CVE-2026-89953",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: mtdoops: free page bitmap when the backing MTD is removed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89953"
    },
    {
      "rank": 833,
      "cve_id": "CVE-2026-89955",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio-ap: Fix NULL deref in status_show() during queue probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89955"
    },
    {
      "rank": 834,
      "cve_id": "CVE-2026-89956",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89956"
    },
    {
      "rank": 835,
      "cve_id": "CVE-2026-89958",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89958"
    },
    {
      "rank": 836,
      "cve_id": "CVE-2026-89962",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/kexec_file: Prevent kexec range truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89962"
    },
    {
      "rank": 837,
      "cve_id": "CVE-2026-89963",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/kexec_file: Fix null-ptr-def in extra size calculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89963"
    },
    {
      "rank": 838,
      "cve_id": "CVE-2026-89964",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "parisc: eisa: Fix infinite loop when parsing invalid IRQ value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89964"
    },
    {
      "rank": 839,
      "cve_id": "CVE-2026-89966",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89966"
    },
    {
      "rank": 840,
      "cve_id": "CVE-2026-89975",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-fabrics: fix DHCHAP secret leak on parse failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89975"
    },
    {
      "rank": 841,
      "cve_id": "CVE-2026-89976",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/ethosu: fix job completion fence cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89976"
    },
    {
      "rank": 842,
      "cve_id": "CVE-2026-89977",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/ethosu: check MMIO mapping errors in probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89977"
    },
    {
      "rank": 843,
      "cve_id": "CVE-2026-89978",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: return early from a zero-length flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89978"
    },
    {
      "rank": 844,
      "cve_id": "CVE-2026-89981",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: Don't read GMID_EL1 when MTE is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89981"
    },
    {
      "rank": 845,
      "cve_id": "CVE-2026-89982",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: mux: Fix channel node leak on adapter add failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89982"
    },
    {
      "rank": 846,
      "cve_id": "CVE-2026-89983",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: core: fix debugfs UAF on adapter removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89983"
    },
    {
      "rank": 847,
      "cve_id": "CVE-2026-89984",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/x86/intel: Fix kernel address leakages in LBR stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89984"
    },
    {
      "rank": 848,
      "cve_id": "CVE-2026-89987",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/huge_memory: transfer the pmd dirty bit to the folio on zap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89987"
    },
    {
      "rank": 849,
      "cve_id": "CVE-2026-89989",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89989"
    },
    {
      "rank": 850,
      "cve_id": "CVE-2026-89991",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix infinite loop in pcpu_freelist push with one possible CPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89991"
    },
    {
      "rank": 851,
      "cve_id": "CVE-2026-89993",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: dw-edma: Initialize IRQ data before requesting IRQs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89993"
    },
    {
      "rank": 852,
      "cve_id": "CVE-2026-89996",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89996"
    },
    {
      "rank": 853,
      "cve_id": "CVE-2026-90004",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/damon/core: handle region split failure in apply_min_nr_regions()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90004"
    },
    {
      "rank": 854,
      "cve_id": "CVE-2026-90005",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "samples/damon/wsse: handle damon_start() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90005"
    },
    {
      "rank": 855,
      "cve_id": "CVE-2026-90006",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "samples/damon/mtier: handle damon_stop() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90006"
    },
    {
      "rank": 856,
      "cve_id": "CVE-2026-90015",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xhci: fix lost bounce buffers on TDs spanning several ring segments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90015"
    },
    {
      "rank": 857,
      "cve_id": "CVE-2026-90019",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: fix null pointer dereference in usb_put_function_instance()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90019"
    },
    {
      "rank": 858,
      "cve_id": "CVE-2026-90020",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90020"
    },
    {
      "rank": 859,
      "cve_id": "CVE-2026-90021",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_midi: initialize work in f_midi_alloc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90021"
    },
    {
      "rank": 860,
      "cve_id": "CVE-2026-90023",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90023"
    },
    {
      "rank": 861,
      "cve_id": "CVE-2026-90024",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90024"
    },
    {
      "rank": 862,
      "cve_id": "CVE-2026-90028",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: typec: hd3ss3220: track VBUS enable state per consumer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90028"
    },
    {
      "rank": 863,
      "cve_id": "CVE-2026-90029",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: storage: realtek_cr: fix use-after-free on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90029"
    },
    {
      "rank": 864,
      "cve_id": "CVE-2026-90031",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb-storage: ene_ub6250: fix race between scan work and probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90031"
    },
    {
      "rank": 865,
      "cve_id": "CVE-2026-90033",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90033"
    },
    {
      "rank": 866,
      "cve_id": "CVE-2026-90034",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: image: mdc800: change kmalloc() to kzalloc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90034"
    },
    {
      "rank": 867,
      "cve_id": "CVE-2026-90035",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: fix division by zero in get_estimated_bw()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90035"
    },
    {
      "rank": 868,
      "cve_id": "CVE-2026-90039",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Guard admin state-revocation walks with NFSD_NET_UP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90039"
    },
    {
      "rank": 869,
      "cve_id": "CVE-2026-90040",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90040"
    },
    {
      "rank": 870,
      "cve_id": "CVE-2026-90999",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Functional Software, Inc.",
      "product": "Sentry Seer",
      "cwe": null,
      "title": "Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90999"
    },
    {
      "rank": 871,
      "cve_id": "CVE-2026-92126",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": null,
      "title": "Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on the classpath of the component that evaluates the script.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92126"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-58704",
      "detail": "ADDED TO KEV — CVE-2026-58704 (Google Android). Remediation due September 19, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-76460",
      "detail": "ADDED TO KEV — CVE-2026-76460 (Cisco Identity Services Engine Software). Remediation due September 19, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-6297",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-6297. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-20211",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-20211. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-20212",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-20212. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-27168",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-27168. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-27170",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-27170. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-27172",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-27172. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-20079",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25550",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-31278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-31278 (supremainc BioStar 2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45186",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45186 (libexpat project libexpat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49114",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49114 (ONNX). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67309",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67309 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67326",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67326 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69097",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69097 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74038",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74038 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74039 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74044 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74046",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74046 (wazuh-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78155",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78155 (OnGres StackGres). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85594",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85594 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85595",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85595 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85596",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85596 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85597",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85597 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85616",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85616 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85617",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85617 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86754",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86754 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86755",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86755 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86756",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86756 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86757",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86757 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86758",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86758 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86759",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86759 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86760",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86760 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86761",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86761 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86762",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86762 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86763",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86763 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86764 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86765 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86766",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86766 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86767",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86767 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86768",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86768 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86769",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86769 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86770",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86770 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86771",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86771 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86772",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86772 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86773",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86773 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86774 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87017",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87017 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87817",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87817 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87818",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87818 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87819",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87819 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87994",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87994 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87995",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87995 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87996",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87996 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87997 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87998 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87999",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87999 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88051",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88051 (tesseract-ocr tesseract). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88052",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88052 (tesseract-ocr tesseract). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88053",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88053 (tesseract-ocr tesseract). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88054",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88054 (tesseract-ocr tesseract). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88765 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89044 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89156",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89156 (PCRE2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89157",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89157 (PCRE2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89160",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89160 (PCRE2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89162",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89162 (PCRE2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90496 (Fengoffice Feng Office). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90501",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90501 (lenve vhr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90506",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90506 (vvbbnn00 WARP-Clash-API). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90511",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90511 (GongShengyue OnlineBooks). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90517",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90517 (PHPGurukul Bank Locker Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90522",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90522 (jaychouchannel Tourism-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90565",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90565 (Rizwan17 inventory-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90573",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90573 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90575",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90575 (PHPGurukul Small CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90598",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90598 (jaygajera17 E-commerce-project-springBoot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90608",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90608 (Totolink A3002MU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90613",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90613 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90619",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90619 (0x4m4 HexStrike AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90685",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90685 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90690",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90690 (0x4m4 HexStrike AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90695",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90695 (SourceCodester Inventory Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90700",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90700 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90705",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90705 (D-Link DWR-M921). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90710 (taisan tarzan-cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90716",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90716 (marcobambini Gravity). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90788",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90788 (magicblack MacCMS10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90793",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90793 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90802",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90802 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90807",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90807 (nanocoai NanoClaw). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90812 (cosmicstack-labs mercury-agent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90818",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90818 (netease-youdao LobsterAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90826",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90826 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90829",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90829 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90831",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90831 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90843 (SabyasachiRana WebMap). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90876",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90876 (SourceCodester Online Faculty Clearance System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90941",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90941 (201206030 novel-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91752",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91752 (GNU libextractor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91781",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91781 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91782",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91782 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0129",
      "detail": "RESCORED — CVE-2026-0129 (Google Android). CVSS 3.5 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0130",
      "detail": "RESCORED — CVE-2026-0130 (Google Android). CVSS 3.5 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0134",
      "detail": "RESCORED — CVE-2026-0134 (Google Android). CVSS 3.3 → 4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0136",
      "detail": "RESCORED — CVE-2026-0136 (Google Android). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0141",
      "detail": "RESCORED — CVE-2026-0141 (Google Android). CVSS 4.3 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0142",
      "detail": "RESCORED — CVE-2026-0142 (Google Android). CVSS 3.3 → 4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0144",
      "detail": "RESCORED — CVE-2026-0144 (Google Android). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0145",
      "detail": "RESCORED — CVE-2026-0145 (Google Android). CVSS 3.3 → 4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0155",
      "detail": "RESCORED — CVE-2026-0155 (Google Android). CVSS 4.3 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0158",
      "detail": "RESCORED — CVE-2026-0158 (Google Android). CVSS 3.3 → 4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-0165",
      "detail": "RESCORED — CVE-2026-0165 (Google Android). CVSS 5.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-27238",
      "detail": "RESCORED — CVE-2026-27238 (Adobe InDesign Desktop). CVSS 5.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55306",
      "detail": "RESCORED — CVE-2026-55306 (Google Android). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56888",
      "detail": "RESCORED — CVE-2026-56888 (Google Android). CVSS 5.5 → 6.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56892",
      "detail": "RESCORED — CVE-2026-56892 (Google Android). CVSS 5.5 → 6.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56975",
      "detail": "RESCORED — CVE-2026-56975 (Google Android). CVSS 5.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57008",
      "detail": "RESCORED — CVE-2026-57008 (Google Android). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58731",
      "detail": "RESCORED — CVE-2026-58731 (Google Android). CVSS 5.5 → 6.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59308",
      "detail": "RESCORED — CVE-2026-59308 (Spring AI). CVSS 4.2 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59318",
      "detail": "RESCORED — CVE-2026-59318 (Spring AI). CVSS 6.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-61908",
      "detail": "RESCORED — CVE-2026-61908 (cyrusimap Cyrus IMAP). CVSS 3.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-61909",
      "detail": "RESCORED — CVE-2026-61909 (cyrusimap Cyrus IMAP). CVSS 3.5 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-61910",
      "detail": "RESCORED — CVE-2026-61910 (cyrusimap Cyrus IMAP). CVSS 3.5 → 5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-61915",
      "detail": "RESCORED — CVE-2026-61915 (cyrusimap Cyrus IMAP). CVSS 4.2 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-63523",
      "detail": "RESCORED — CVE-2026-63523 (Microsoft Skype for Business Server 2015 CU13). CVSS 6.5 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69642",
      "detail": "RESCORED — CVE-2026-69642 (Microsoft Skype for Business Server 2015 CU13). CVSS 6.5 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69820",
      "detail": "RESCORED — CVE-2026-69820 (Microsoft Windows 10 Version 21H2). CVSS 8.2 → 6.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69832",
      "detail": "RESCORED — CVE-2026-69832 (Microsoft Windows 10 Version 1607). CVSS 5.6 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69874",
      "detail": "RESCORED — CVE-2026-69874 (Microsoft Windows 10 Version 1809). CVSS 8.2 → 6.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77584",
      "detail": "RESCORED — CVE-2026-77584 (torproject Tor). CVSS 7 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77587",
      "detail": "RESCORED — CVE-2026-77587 (torproject Tor). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77638",
      "detail": "RESCORED — CVE-2026-77638 (torproject Tor). CVSS 8.9 → 9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78135",
      "detail": "RESCORED — CVE-2026-78135 (strongSwan). CVSS 5.6 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80378",
      "detail": "RESCORED — CVE-2026-80378 (IBM DataStage on Cloud Pak for Data). CVSS 8.5 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80434",
      "detail": "RESCORED — CVE-2026-80434 (IBM DataStage on Cloud Pak for Data). CVSS 7.4 → 5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81048",
      "detail": "RESCORED — CVE-2026-81048 (Dell ThinOS 10). CVSS 9.6 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81049",
      "detail": "RESCORED — CVE-2026-81049 (Dell ThinOS 10). CVSS 4.4 → 6.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81468",
      "detail": "RESCORED — CVE-2026-81468 (Dell ThinOS 10). CVSS 9.1 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81551",
      "detail": "RESCORED — CVE-2026-81551 (IBM DataStage on Cloud Pak for Data). CVSS 8.8 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81554",
      "detail": "RESCORED — CVE-2026-81554 (IBM DataStage on Cloud Pak for Data). CVSS 8.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82092",
      "detail": "RESCORED — CVE-2026-82092 (IBM DataStage on Cloud Pak for Data). CVSS 8.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82100",
      "detail": "RESCORED — CVE-2026-82100 (IBM DataStage on Cloud Pak for Data). CVSS 9.6 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-83941",
      "detail": "RESCORED — CVE-2026-83941 (Microsoft Entra). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-89156",
      "detail": "RESCORED — CVE-2026-89156 (PCRE2). CVSS 2.9 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-89157",
      "detail": "RESCORED — CVE-2026-89157 (PCRE2). CVSS 5.7 → 7.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-89160",
      "detail": "RESCORED — CVE-2026-89160 (PCRE2). CVSS 3.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-89161",
      "detail": "RESCORED — CVE-2026-89161 (PCRE2). CVSS 7.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-89162",
      "detail": "RESCORED — CVE-2026-89162 (PCRE2). CVSS 2.9 → 3.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-9336",
      "detail": "RESCORED — CVE-2026-9336 (IBM WebSphere Application Server). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-74259",
      "detail": "REJECTED — CVE-2026-74259 (Linux). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15709",
      "detail": "PATCH SHIPPED — CVE-2026-15709 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.6.5-3.el10_2.14."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15711",
      "detail": "PATCH SHIPPED — CVE-2026-15711 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.6.5-3.el10_2.14."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15945",
      "detail": "PATCH SHIPPED — CVE-2026-15945 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16072",
      "detail": "PATCH SHIPPED — CVE-2026-16072 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16089",
      "detail": "PATCH SHIPPED — CVE-2026-16089 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16093",
      "detail": "PATCH SHIPPED — CVE-2026-16093 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16104",
      "detail": "PATCH SHIPPED — CVE-2026-16104 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16105",
      "detail": "PATCH SHIPPED — CVE-2026-16105 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16106",
      "detail": "PATCH SHIPPED — CVE-2026-16106 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-16108",
      "detail": "PATCH SHIPPED — CVE-2026-16108 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-17059",
      "detail": "PATCH SHIPPED — CVE-2026-17059 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-17615",
      "detail": "PATCH SHIPPED — CVE-2026-17615 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18201",
      "detail": "PATCH SHIPPED — CVE-2026-18201 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18209",
      "detail": "PATCH SHIPPED — CVE-2026-18209 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18214",
      "detail": "PATCH SHIPPED — CVE-2026-18214 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18215",
      "detail": "PATCH SHIPPED — CVE-2026-18215 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18218",
      "detail": "PATCH SHIPPED — CVE-2026-18218 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18570",
      "detail": "PATCH SHIPPED — CVE-2026-18570 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18571",
      "detail": "PATCH SHIPPED — CVE-2026-18571 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18572",
      "detail": "PATCH SHIPPED — CVE-2026-18572 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18573",
      "detail": "PATCH SHIPPED — CVE-2026-18573 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18917",
      "detail": "PATCH SHIPPED — CVE-2026-18917 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:10.10.0-8.12.el10_0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-19729",
      "detail": "PATCH SHIPPED — CVE-2026-19729 (Red Hat build of Keycloak 26.4). Fixed in Red Hat build of Keycloak 26.4 26.4.16-2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-79652",
      "detail": "PATCH SHIPPED — CVE-2026-79652 (Red Hat build of Keycloak 26.6). Fixed in Red Hat build of Keycloak 26.6 26.6.7-3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-81665",
      "detail": "PATCH SHIPPED — CVE-2026-81665 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.1.10-1.el10_2.2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-85197",
      "detail": "PATCH SHIPPED — CVE-2026-85197 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.6.5-3.el10_2.14."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2017-17537",
      "detail": "ENRICHED — CVE-2017-17537. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2017-6297",
      "detail": "ENRICHED — CVE-2017-6297. Received CVSS 5.9 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-20211",
      "detail": "ENRICHED — CVE-2020-20211. Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-20212",
      "detail": "ENRICHED — CVE-2020-20212. Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2023-27169",
      "detail": "ENRICHED — CVE-2023-27169. Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2023-27170",
      "detail": "ENRICHED — CVE-2023-27170. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43789",
      "detail": "ENRICHED — CVE-2026-43789 (Apple macOS). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43790",
      "detail": "ENRICHED — CVE-2026-43790 (Apple macOS). Received CVSS 9.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43791",
      "detail": "ENRICHED — CVE-2026-43791 (Apple macOS). Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43815",
      "detail": "ENRICHED — CVE-2026-43815 (Apple macOS). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-65342",
      "detail": "ENRICHED — CVE-2026-65342 (Apple macOS). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-65378",
      "detail": "ENRICHED — CVE-2026-65378 (Apple macOS). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-65381",
      "detail": "ENRICHED — CVE-2026-65381 (Apple macOS). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-65382",
      "detail": "ENRICHED — CVE-2026-65382 (Apple macOS). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-65383",
      "detail": "ENRICHED — CVE-2026-65383 (Apple macOS). Received CVSS 4.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84522",
      "detail": "ENRICHED — CVE-2026-84522 (Apple macOS). Received CVSS 5.9 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84533",
      "detail": "ENRICHED — CVE-2026-84533 (Apple iOS and iPadOS). Received CVSS 5.3 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84540",
      "detail": "ENRICHED — CVE-2026-84540 (Apple macOS). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84544",
      "detail": "ENRICHED — CVE-2026-84544 (Apple macOS). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84548",
      "detail": "ENRICHED — CVE-2026-84548 (Apple macOS). Received CVSS 7.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84549",
      "detail": "ENRICHED — CVE-2026-84549 (Apple macOS). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84551",
      "detail": "ENRICHED — CVE-2026-84551 (Apple iOS and iPadOS). Received CVSS 4.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84552",
      "detail": "ENRICHED — CVE-2026-84552 (Apple iOS and iPadOS). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84558",
      "detail": "ENRICHED — CVE-2026-84558 (Apple macOS). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84565",
      "detail": "ENRICHED — CVE-2026-84565 (Apple macOS). Received CVSS 7.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84569",
      "detail": "ENRICHED — CVE-2026-84569 (Apple macOS). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84580",
      "detail": "ENRICHED — CVE-2026-84580 (Apple macOS). Received CVSS 8.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84584",
      "detail": "ENRICHED — CVE-2026-84584 (Apple macOS). Received CVSS 8.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-84601",
      "detail": "ENRICHED — CVE-2026-84601 (Apple macOS). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
