{
  "day": "2026-09-17",
  "boundary": "UTC calendar day",
  "published_count": 1035,
  "by_severity": {
    "CRITICAL": 71,
    "HIGH": 177,
    "MEDIUM": 133,
    "LOW": 29
  },
  "kev_count": 1,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 625,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-87886",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-09-19",
      "vendor": "Acronis",
      "product": "Acronis Backup plugin for cPanel & WHM",
      "cwe": "CWE-276",
      "title": "Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87886"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-87796",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00611,
      "epss_percentile": 0.47684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sh1zen",
      "product": "Multi Uploader for Gravity Forms",
      "cwe": "CWE-434",
      "title": "Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87796"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-87935",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00533,
      "epss_percentile": 0.43753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ichurakov",
      "product": "Paid Downloads",
      "cwe": "CWE-434",
      "title": "Paid Downloads <= 3.15 - Unauthenticated Arbitrary File Upload via 'paiddownloads_update_file' Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87935"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-90982",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.29359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/static",
      "product": "@fastify/static",
      "cwe": "CWE-178",
      "title": "@fastify/static vulnerable to route guard bypass via path case-folding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90982"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-78427",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.29369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go",
      "product": "github.com/neuvector/neuvector",
      "cwe": "CWE-807",
      "title": "Admission Control Bypass via Hardcoded Sidecar Image Exemption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78427"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-78425",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go",
      "product": "github.com/neuvector/neuvector",
      "cwe": "CWE-287",
      "title": "SAML Audience Confusion Allows Cross-SP Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78425"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-89064",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "servmask",
      "product": "All-in-One WP Migration and Backup",
      "cwe": "CWE-522",
      "title": "All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Insufficient Credential Protection via Authorization Basic Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89064"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-78428",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.27209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go",
      "product": "neuvector",
      "cwe": "CWE-384",
      "title": "Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78428"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-86801",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "To Do List Member",
      "cwe": "CWE-306",
      "title": "To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86801"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-87963",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Yo",
      "cwe": null,
      "title": "Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87963"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-25275",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in WLAN Firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25275"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-88795",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.2188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wpShopGermany IT-RECHT KANZLEI",
      "cwe": "CWE-94",
      "title": "wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88795"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-50607",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00253,
      "epss_percentile": 0.16968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "System Monitoring",
      "cwe": "CWE-668",
      "title": "WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50607"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-86320",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.1247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-94",
      "title": "Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86320"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-92839",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.11908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canva",
      "product": "Canva",
      "cwe": "CWE-174",
      "title": "Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92839"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-86311",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Photo Gallery by 10Web – Mobile-Friendly Image Gallery",
      "cwe": "CWE-79",
      "title": "Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86311"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-78426",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go",
      "product": "neuvector",
      "cwe": "CWE-863",
      "title": "Logout bypass via alternate JWT spelling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78426"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-86709",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00177,
      "epss_percentile": 0.07468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "The Pressengine",
      "cwe": "CWE-287",
      "title": "The Pressengine <= 1.0 - Unauthenticated Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86709"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-85130",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPLP Cookie Consent",
      "cwe": "CWE-79",
      "title": "WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85130"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-87786",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dewa Kirim",
      "cwe": "CWE-79",
      "title": "Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87786"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-88792",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dictionary",
      "cwe": "CWE-79",
      "title": "Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88792"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2025-15697",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dictionary",
      "cwe": "CWE-79",
      "title": "Dictionary <= 1.0 - Reflected XSS via Multiple Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15697"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-91014",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Realtyna Organic IDX plugin + WPL Real Estate",
      "cwe": "CWE-79",
      "title": "Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91014"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-24073",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Video",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24073"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-24074",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Video",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24074"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-91011",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "EWWW Image Optimizer",
      "cwe": "CWE-79",
      "title": "EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91011"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-24081",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in BT Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24081"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-25281",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in OOBM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25281"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-25294",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in WLAN Firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25294"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-86788",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "HT Mega Addons for Elementor",
      "cwe": "CWE-79",
      "title": "HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86788"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-87829",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Checkout Field Manager (Checkout Manager) for WooCommerce",
      "cwe": "CWE-639",
      "title": "Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87829"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-87831",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Checkout Field Manager (Checkout Manager) for WooCommerce",
      "cwe": "CWE-862",
      "title": "Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87831"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-86446",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00145,
      "epss_percentile": 0.04196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": "CWE-200",
      "title": "LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86446"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-50604",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Agent Service",
      "cwe": "CWE-306",
      "title": "Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50604"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-50608",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "System Monitoring",
      "cwe": "CWE-306",
      "title": "Authentication Vulnerability in NitroSense and PredatorSense Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50608"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-92838",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-Remote E-map",
      "cwe": "CWE-427",
      "title": "GeoVision GV-Remote E-Map dll hijacking vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92838"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-87836",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00139,
      "epss_percentile": 0.03669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Comments Import & Export",
      "cwe": "CWE-200",
      "title": "Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87836"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-86707",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Private Feed Key",
      "cwe": "CWE-287",
      "title": "Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86707"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-86710",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Login with QR",
      "cwe": "CWE-287",
      "title": "Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86710"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-85128",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Choose User Role at Registration",
      "cwe": "CWE-269",
      "title": "Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85128"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-90923",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Autopay",
      "cwe": "CWE-863",
      "title": "Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90923"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-90922",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paid Membership Subscriptions",
      "cwe": "CWE-284",
      "title": "Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90922"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-91015",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Master Addons for Elementor",
      "cwe": "CWE-862",
      "title": "Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91015"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-91016",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Motors",
      "cwe": "CWE-639",
      "title": "Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91016"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-91008",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Booking Manager for WooCommerce",
      "cwe": "CWE-639",
      "title": "Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91008"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-44940",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "SUSE Observability",
      "cwe": "CWE-200",
      "title": "Service token exposure and potential privilege escalation in SUSE Observability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44940"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-88904",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PuppyFW",
      "cwe": "CWE-269",
      "title": "PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88904"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-91019",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Booking Manager for WooCommerce",
      "cwe": "CWE-284",
      "title": "Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91019"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-91010",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms",
      "cwe": "CWE-862",
      "title": "Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91010"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-15688",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00119,
      "epss_percentile": 0.01982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitsubishi Electric Corporation",
      "product": "GX Works3",
      "cwe": "CWE-303",
      "title": "Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15688"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-25261",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-822",
      "title": "Untrusted Pointer Dereference in Camera",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25261"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-25283",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in OOBM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25283"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2025-59607",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-822",
      "title": "Untrusted Pointer Dereference in Windows Compute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59607"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-24075",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in Qualcomm IPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24075"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-25280",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25280"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-25290",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-190",
      "title": "Integer Overflow or Wraparound in OOBM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25290"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-81546",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canva",
      "product": "Affinity",
      "cwe": "CWE-121",
      "title": "The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81546"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-25284",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in OOBM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25284"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-91017",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Robokassa payment gateway for Woocommerce",
      "cwe": "CWE-345",
      "title": "Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91017"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-86824",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletter",
      "cwe": "CWE-326",
      "title": "Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86824"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-25282",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in OOBM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25282"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-91009",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Active Woot Products Tables for WooCommerce. 100% FREE",
      "cwe": "CWE-352",
      "title": "Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91009"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-50605",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Agent Serivce",
      "cwe": "CWE-284",
      "title": "Privilege Escalation Vulnerability in NitroSense and PredatorSense Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50605"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-50609",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "System Monitoring",
      "cwe": "CWE-284",
      "title": "Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50609"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-50610",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "System Monitoring",
      "cwe": "CWE-284",
      "title": "Improper Access control Vulnerability in NitroSense and PredatorSense Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50610"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-25278",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00088,
      "epss_percentile": 0.00444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive Software platform based on QNX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25278"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-50603",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00072,
      "epss_percentile": 0.00065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Agent Service",
      "cwe": "CWE-321",
      "title": "Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSense",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50603"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-50606",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00072,
      "epss_percentile": 0.00065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "System Monitoring",
      "cwe": "CWE-321",
      "title": "Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and PredatorSense Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50606"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-54734",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prebid",
      "product": "prebid-server-java",
      "cwe": "CWE-918",
      "title": "Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54734"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-62104",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "superweby",
      "product": "Migratico Lite",
      "cwe": "CWE-94",
      "title": "WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62104"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-62874",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Billing",
      "cwe": "CWE-345",
      "title": "Azure Billing Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62874"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-69399",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure ARC",
      "cwe": "CWE-441",
      "title": "Azure Arc Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69399"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-69843",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Fabric",
      "cwe": "CWE-290",
      "title": "Microsoft Fabric Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69843"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-69865",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Container Registry",
      "cwe": "CWE-639",
      "title": "Microsoft Container Registry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69865"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-70200",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Logic Apps",
      "cwe": "CWE-22",
      "title": "Azure Logic Apps Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70200"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-83944",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Logic Apps",
      "cwe": "CWE-284",
      "title": "Azure Logic Apps Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83944"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-85889",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure AI Foundry",
      "cwe": "CWE-306",
      "title": "Azure AI Foundry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85889"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-92937",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-94",
      "title": "vm2 3.11.6 Remote Code Execution via Promise call/apply",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92937"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-92940",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-668",
      "title": "vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92940"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-92941",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-732",
      "title": "vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92941"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-92946",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2 before 3.11.7 Remote Code Execution via require.external",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92946"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-92947",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-200",
      "title": "vm2 before 3.11.7 Memory Disclosure via Buffer Pool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92947"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-92955",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2 before 3.11.8 Sandbox Escape via NodeVM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92955"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-92956",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92956"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-92960",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-200",
      "title": "vm2 before 3.11.6 Process-wide State Exposure via os and dns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92960"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-85878",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure HorizonDB",
      "cwe": "CWE-285",
      "title": "Azure Database for PostgreSQL Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85878"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-85885",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-77",
      "title": "Microsoft 365 Copilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85885"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-45140",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chamilo",
      "product": "chamilo-lms",
      "cwe": "CWE-22",
      "title": "Chamilo LMS CStudio upload flow allows unauthenticated remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45140"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-54460",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-reception",
      "product": "appointment-booking-software",
      "cwe": "CWE-306",
      "title": "OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54460"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-54617",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GravitLauncher",
      "product": "Launcher",
      "cwe": "CWE-22",
      "title": "GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54617"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-54626",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HappySeaFox",
      "product": "sail",
      "cwe": "CWE-122",
      "title": "SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54626"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-54627",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HappySeaFox",
      "product": "sail",
      "cwe": "CWE-122",
      "title": "SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54627"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-62101",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chris Åkerfeldt Wendel",
      "product": "EduAdmin Booking",
      "cwe": "CWE-288",
      "title": "WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62101"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-62108",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "Headless Single Sign On",
      "cwe": "CWE-290",
      "title": "WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62108"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-90822",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FatPipe Networks",
      "product": "MPVPN",
      "cwe": "CWE-78",
      "title": "FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90822"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-90823",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FatPipe Networks",
      "product": "MPVPN",
      "cwe": "CWE-121",
      "title": "FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90823"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-54053",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brufdev",
      "product": "many-notes",
      "cwe": "CWE-22",
      "title": "Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54053"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-54752",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netbox-community",
      "product": "devicetype-library",
      "cwe": "CWE-502",
      "title": "NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54752"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-87701",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Cosmos DB",
      "cwe": "CWE-74",
      "title": "Azure Cosmos DB Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87701"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-92934",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 before 3.11.8 Sandbox Escape RCE via AggregateError",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92934"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-92935",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2 NodeVM Remote Code Execution via Array-Shaped Require",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92935"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-54501",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webrecorder",
      "product": "browsertrix",
      "cwe": "CWE-20",
      "title": "Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54501"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-54618",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jimprosser",
      "product": "obsidian-web-mcp",
      "cwe": "CWE-306",
      "title": "Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54618"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-92860",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rcourtman",
      "product": "Pulse",
      "cwe": "CWE-20",
      "title": "rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92860"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-92938",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92938"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-92939",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-114",
      "title": "vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92939"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-92948",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92948"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-92951",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-706",
      "title": "vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92951"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-92957",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-269",
      "title": "vm2 before 3.11.7 Authentication Bypass via node: Prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92957"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-54237",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wavelog",
      "product": "wavelog",
      "cwe": "CWE-94",
      "title": "Wavelog: Unauthenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54237"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-70009",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure ARC",
      "cwe": "CWE-22",
      "title": "Azure Arc Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70009"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-86863",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-290",
      "title": "pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86863"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-92944",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92944"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-92950",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-453",
      "title": "vm2 before 3.11.7 Sandbox Escape via CLI require",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92950"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-92953",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92953"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-76834",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "b2evolution",
      "product": "b2evolution CMS",
      "cwe": "CWE-502",
      "title": "b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76834"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-79752",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "cakephp",
      "cwe": "CWE-89",
      "title": "CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79752"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-92943",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWSIoTPythonSDK",
      "cwe": "CWE-297",
      "title": "Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92943"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-92954",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-248",
      "title": "vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92954"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-93393",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "C Driver",
      "cwe": "CWE-787",
      "title": "Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93393"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-54670",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LabRedesCefetRJ",
      "product": "WeGIA",
      "cwe": "CWE-22",
      "title": "WeGIA: Unauthenticated Auth Bypass + Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54670"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-54767",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LabRedesCefetRJ",
      "product": "WeGIA",
      "cwe": "CWE-306",
      "title": "WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54767"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-63472",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vendurehq",
      "product": "vendure",
      "cwe": "CWE-287",
      "title": "Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63472"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-76949",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-290",
      "title": "Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76949"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-82761",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-367",
      "title": "Magic link single-use tokens replayable via TOCTOU race in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82761"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-85500",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-305",
      "title": "`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85500"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-86533",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-613",
      "title": "Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86533"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-88952",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-287",
      "title": "OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88952"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-91039",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-290",
      "title": "dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91039"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-92913",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-330",
      "title": "AVideo Weak PRNG Activation Code Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92913"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-45143",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chamilo",
      "product": "chamilo-lms",
      "cwe": "CWE-79",
      "title": "Chamilo LMS: Student-to-admin stored XSS in private messages via v-html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45143"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-47252",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "julien040",
      "product": "anyquery",
      "cwe": "CWE-94",
      "title": "Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47252"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-77903",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dataverse",
      "cwe": "CWE-290",
      "title": "Microsoft Dataverse Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77903"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-92952",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-669",
      "title": "vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92952"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-14850",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MobiAPParc",
      "product": "MobiAPParc",
      "cwe": "CWE-640",
      "title": "Weak password recovery mechanism for forgotten password in MobiAPParc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14850"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-15815",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-22",
      "title": "CVE-2026-15815 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15815"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-28326",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Access Rights Manager",
      "cwe": "CWE-321",
      "title": "SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28326"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-54239",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpengine",
      "product": "faustjs",
      "cwe": "CWE-345",
      "title": "FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54239"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-54504",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andrea9293",
      "product": "mcp-documentation-server",
      "cwe": "CWE-306",
      "title": "MCP Documentation Server: Web UI API binds to all interfaces without authentication by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54504"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-54519",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vmDeshpande",
      "product": "ai-agent-automation",
      "cwe": "CWE-862",
      "title": "AI Agent Automation: Missing ownership checks in memory APIs allow cross-user memory read and deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54519"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-54612",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-22",
      "title": "Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-save-global",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54612"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-54671",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LabRedesCefetRJ",
      "product": "WeGIA",
      "cwe": "CWE-639",
      "title": "WeGIA: Authorization Bypass via Empty Resource Array in InternoControle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54671"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-54916",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netbox-community",
      "product": "devicetype-library",
      "cwe": "CWE-427",
      "title": "NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54916"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-77614",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opencast",
      "product": "opencast",
      "cwe": "CWE-384",
      "title": "Opencast: Session fixation in login enables account takeover via crafted link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77614"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-78295",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xagio SEO",
      "product": "Xagio SEO",
      "cwe": "CWE-352",
      "title": "WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78295"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-92972",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgl-project",
      "product": "sglang",
      "cwe": "CWE-306",
      "title": "SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92972"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-52836",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenDDS",
      "product": "OpenDDS",
      "cwe": "CWE-125",
      "title": "OpenDDS: out-of-bounds `rd_ptr` dereference in `RtpsSampleHeader::init` — triggered by malformed RTPS submessage, remotely exploitable denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52836"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-54343",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "lms",
      "cwe": "CWE-22",
      "title": "Frappe LMS: Path Traversal in SCORM File Serving",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54343"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-54571",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ESP32Async",
      "product": "ESPAsyncWebServer",
      "cwe": "CWE-190",
      "title": "ESPAsyncWebServer: Integer overflow in multipart boundary parser causes denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54571"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-63459",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vendurehq",
      "product": "vendure",
      "cwe": "CWE-79",
      "title": "Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63459"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-69197",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "umbraco",
      "product": "Umbraco-CMS",
      "cwe": "CWE-200",
      "title": "Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69197"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-77615",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opencast",
      "product": "opencast",
      "cwe": "CWE-79",
      "title": "Paella Player: Stored XSS via caption cue text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77615"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-86864",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-22",
      "title": "pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86864"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-89036",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appwrite",
      "product": "appwrite",
      "cwe": "CWE-88",
      "title": "Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89036"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-89418",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "protobuf-javascript (aka google-protobuf npm package)",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion leading to Denial of Service in protobuf-javascript (google-protobuf)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89418"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-92916",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-200",
      "title": "Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92916"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-92917",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-200",
      "title": "Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92917"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-92918",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cjbi",
      "product": "admin3",
      "cwe": "CWE-532",
      "title": "admin3 through 3.0.0 Session Token Disclosure via Audit Log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92918"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-92942",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-400",
      "title": "vm2 before 3.11.7 Timeout Bypass via FinalizationRegistry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92942"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-92961",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-770",
      "title": "vm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92961"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-92970",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hubzero",
      "product": "hubzero-cms",
      "cwe": "CWE-22",
      "title": "HUBzero CMS through 2.2.32 Path Traversal via File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92970"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-92971",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-617",
      "title": "InternLM LMDeploy through 0.17.0 Assertion Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92971"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-92983",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-772",
      "title": "InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92983"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-92987",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RazrFalcon",
      "product": "roxmltree",
      "cwe": "CWE-407",
      "title": "roxmltree through 0.21.1 Denial of Service via Quadratic Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92987"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-93435",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NodeRedis",
      "product": "redis-parser",
      "cwe": "CWE-674",
      "title": "redis-parser through 3.0.0 Denial of Service via Unbounded Recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93435"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-93436",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-401",
      "title": "vLLM through 0.29.0 Memory Exhaustion via Rejected Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93436"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-93450",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-openapi",
      "product": "swag",
      "cwe": "CWE-674",
      "title": "go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93450"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-93452",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xerial",
      "product": "snappy-java",
      "cwe": "CWE-787",
      "title": "snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93452"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-93453",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alinto",
      "product": "SOGo",
      "cwe": "CWE-640",
      "title": "SOGo before 5.12.11 Password Reset Token Interception via Origin Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93453"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-19477",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MCC",
      "product": "Universal Library for Linux (uldaq)",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow Vulnerability in Linux (uldaq)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19477"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-68791",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Machine Learning",
      "cwe": "CWE-863",
      "title": "Azure Machine Learning Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68791"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-92914",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-287",
      "title": "AVideo LoginControl PGP Second Factor Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92914"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-92980",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danielbrendel",
      "product": "hortusfox-web",
      "cwe": "CWE-434",
      "title": "HortusFox-Web < 6.1 Remote Code Execution via Import/Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92980"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-92985",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92985"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-92986",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before 3.8.4 Cross-Site Scripting via Document Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92986"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-66580",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RexTheme",
      "product": "Product Feed Manager",
      "cwe": "CWE-89",
      "title": "WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66580"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-71538",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CycloneDX",
      "product": "cyclonedx-node-npm",
      "cwe": "CWE-78",
      "title": "@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71538"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-92984",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hubzero",
      "product": "hubzero-cms",
      "cwe": "CWE-384",
      "title": "HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92984"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-93337",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nm-l2tp",
      "product": "NetworkManager-l2tp",
      "cwe": "CWE-88",
      "title": "NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93337"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-54507",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-918",
      "title": "Vvveb oEmbedProxy vulnerable to server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54507"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-55062",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uniget-org",
      "product": "cli",
      "cwe": "CWE-22",
      "title": "uniget: Path Traversal in Hook Files - Directory Escape Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55062"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-92958",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-269",
      "title": "vm2 before 3.11.7 Denylist Bypass via fs/promises",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92958"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-93292",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-89",
      "title": "SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93292"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-93426",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-89",
      "title": "SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93426"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-54580",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-354",
      "title": "mport index decompression can leave partial or corrupt index data after zstd failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54580"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-54581",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-345",
      "title": "mport bootstrap index fetch can continue after hash verification failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54581"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-54583",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-22",
      "title": "mport package bundle downloads allow unsafe destination filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54583"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-54597",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itflow-org",
      "product": "itflow",
      "cwe": "CWE-89",
      "title": "ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54597"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-92912",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-330",
      "title": "AVideo Cryptographically Weak PRNG via uniqid Stream Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92912"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-54253",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joni1802",
      "product": "ts3-manager",
      "cwe": "CWE-79",
      "title": "TS3 Manager: Reflected XSS via /api/download port parameter steals operator session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54253"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-54354",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MapServer",
      "product": "MapServer",
      "cwe": "CWE-89",
      "title": "MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query Translation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54354"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-54451",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-protobuf",
      "product": "protobuf",
      "cwe": "CWE-674",
      "title": "Elixir protobuf: Unbounded recursion depth in embedded-message decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54451"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-56795",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Driver Pack For Windows OS",
      "cwe": "CWE-427",
      "title": "Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56795"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-82760",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-407",
      "title": "Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82760"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-83946",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Portal",
      "cwe": "CWE-79",
      "title": "Azure Portal Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83946"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-85077",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sanic-org",
      "product": "sanic",
      "cwe": "CWE-113",
      "title": "Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85077"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-86039",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "js-libp2p",
      "cwe": "CWE-290",
      "title": "libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86039"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-92903",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-89",
      "title": "Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Controlled Values to be Interpolated into SQL Strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92903"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-26950",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "SmartFabric Manager",
      "cwe": "CWE-345",
      "title": "Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26950"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-54446",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Labs64",
      "product": "NetLicensing-MCP",
      "cwe": "CWE-306",
      "title": "NetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54446"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-54520",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vmDeshpande",
      "product": "ai-agent-automation",
      "cwe": "CWE-22",
      "title": "AI Agent Automation: Workflow file step path traversal allows read and write outside the expected directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54520"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-54596",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itflow-org",
      "product": "itflow",
      "cwe": "CWE-89",
      "title": "ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54596"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-81442",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-269",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81442"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-81475",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-306",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81475"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-81476",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-78",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81476"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-81478",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-321",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81478"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-54692",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HappySeaFox",
      "product": "sail",
      "cwe": "CWE-131",
      "title": "SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal buffer (heap out-of-bounds write)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54692"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-81474",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-122",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81474"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-48977",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openslide",
      "product": "openslide",
      "cwe": "CWE-123",
      "title": "OpenSlide: Arbitrary memory write with crafted Ventana BIF file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48977"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-50158",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eat-pray-ai",
      "product": "yutu",
      "cwe": "CWE-73",
      "title": "yutu: Arbitrary File Write via MCP `caption-download` Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50158"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-53557",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "SQLBot",
      "cwe": "CWE-89",
      "title": "SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53557"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-54339",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LeslieLeung",
      "product": "glean",
      "cwe": "CWE-918",
      "title": "Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via Malicious RSS Feed in /api/feeds/discover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54339"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-85887",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-732",
      "title": "M365 Copilot Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85887"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-45726",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siderolabs",
      "product": "omni",
      "cwe": "CWE-200",
      "title": "Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45726"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-54506",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-79",
      "title": "Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54506"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-66618",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flipper Code",
      "product": "WP Maps",
      "cwe": "CWE-89",
      "title": "WordPress WP Maps plugin <= 4.9.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66618"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-66619",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tribulant Software",
      "product": "Newsletters",
      "cwe": "CWE-89",
      "title": "WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66619"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-66624",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ludwig You",
      "product": "WPMasterToolKit",
      "cwe": "CWE-89",
      "title": "WordPress WPMasterToolKit plugin <= 2.22.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66624"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-66625",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WCVendors",
      "product": "WC Vendors Marketplace",
      "cwe": "CWE-89",
      "title": "WordPress WC Vendors Marketplace plugin <= 2.7.2.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66625"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-66626",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonal S Sinha",
      "product": "SKT Addons for Elementor",
      "cwe": "CWE-89",
      "title": "WordPress SKT Addons for Elementor plugin <= 4.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66626"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-66628",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Lab",
      "product": "WP-Lister Lite for eBay",
      "cwe": "CWE-89",
      "title": "WordPress WP-Lister Lite for eBay plugin <= 3.8.11 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66628"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-66630",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Series",
      "cwe": "CWE-89",
      "title": "WordPress PublishPress Series plugin <= 3.1.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66630"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-66631",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moreconvert Team",
      "product": "MC Woocommerce Wishlist",
      "cwe": "CWE-89",
      "title": "WordPress MC Woocommerce Wishlist plugin <= 1.9.21 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66631"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-80218",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-287",
      "title": "Sign-in token minted for one resource accepted by another in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80218"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-82685",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-639",
      "title": "Confirmation token accepted on any record in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82685"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-50125",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StacklokLabs",
      "product": "mkp",
      "cwe": "CWE-400",
      "title": "MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50125"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-50275",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-php",
      "cwe": "CWE-770",
      "title": "Datadog PHP Tracer: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50275"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-50277",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-cpp",
      "cwe": "CWE-770",
      "title": "dd-trace-cpp: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50277"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-50285",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pomerium",
      "product": "pomerium",
      "cwe": "CWE-770",
      "title": "Pomerium: Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50285"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-53534",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JabRef",
      "product": "jabref",
      "cwe": "CWE-78",
      "title": "JabRef CAYW Sublime Text integration permits operating-system command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53534"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-54716",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valhalla",
      "product": "valhalla",
      "cwe": "CWE-770",
      "title": "Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54716"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-63460",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vendurehq",
      "product": "vendure",
      "cwe": "CWE-1333",
      "title": "Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63460"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-68523",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fulgur-rs",
      "product": "fulgur",
      "cwe": "CWE-400",
      "title": "Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68523"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-68537",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fulgur-rs",
      "product": "fulgur",
      "cwe": "CWE-400",
      "title": "Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68537"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-81481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-22",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81481"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-81515",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "security-advisories",
      "cwe": "CWE-755",
      "title": "Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81515"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-81516",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "security-advisories",
      "cwe": "CWE-755",
      "title": "Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81516"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-85715",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mattiasw",
      "product": "ExifReader",
      "cwe": "CWE-789",
      "title": "ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85715"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-85719",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-319",
      "title": "AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85719"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-85721",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-400",
      "title": "AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85721"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-85917",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure AI Foundry",
      "cwe": "CWE-918",
      "title": "Azure AI Foundry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85917"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-86038",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "js-libp2p",
      "cwe": "CWE-345",
      "title": "libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86038"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-86040",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "js-libp2p",
      "cwe": "CWE-400",
      "title": "libp2p: Unbounded RPC decode + synchronous subscription processing in @libp2p/floodsub allows unauthenticated DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86040"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-87742",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Exploit Intelligence",
      "cwe": "CWE-770",
      "title": "Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next via unbounded message buffering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87742"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-78501",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot's Business Chat",
      "cwe": "CWE-77",
      "title": "Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78501"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-81446",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-918",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81446"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-86688",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-384",
      "title": "Session id is not renewed on authentication in ash_authentication, allowing session fixation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86688"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-90997",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Keycloak",
      "product": "Keycloak",
      "cwe": "CWE-294",
      "title": "Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90997"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-53554",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "SQLBot",
      "cwe": "CWE-22",
      "title": "SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53554"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-54634",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hamlib",
      "product": "Hamlib",
      "cwe": "CWE-787",
      "title": "Hamlib: rigctld `send_raw` Stack Out-of-Bounds Write and Uninitialized Memory Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54634"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-66269",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-470",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66269"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-76154",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-79",
      "title": "CVE-2026-76154 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76154"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-80356",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-200",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80356"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-81440",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-798",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81440"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-52727",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lxc",
      "product": "lxc-ci",
      "cwe": "CWE-321",
      "title": "lxc-ci: Pacman keyring stored in archlinux image with a private key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52727"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-54646",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cubecart",
      "product": "v6",
      "cwe": "CWE-89",
      "title": "CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54646"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-54647",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cubecart",
      "product": "v6",
      "cwe": "CWE-89",
      "title": "CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54647"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-81445",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-269",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81445"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-81477",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-122",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81477"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-81480",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-121",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81480"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-81632",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication_phoenix",
      "cwe": "CWE-598",
      "title": "Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81632"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-92919",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cjbi",
      "product": "admin3",
      "cwe": "CWE-22",
      "title": "admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92919"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-44236",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alanxz",
      "product": "rabbitmq-c",
      "cwe": "CWE-122",
      "title": "rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44236"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-52851",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traccar",
      "product": "traccar",
      "cwe": "CWE-89",
      "title": "Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52851"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-54510",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "murtaza-nasir",
      "product": "speakr",
      "cwe": "CWE-287",
      "title": "Speakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54510"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-54524",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "hrms",
      "cwe": "CWE-89",
      "title": "Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54524"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-54608",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MythicalLTD",
      "product": "MythicalDash",
      "cwe": "CWE-345",
      "title": "MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpoint allows arbitrary free credit top-up",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54608"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-66571",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gabe Livan",
      "product": "Asset CleanUp: Page Speed Booster",
      "cwe": "CWE-352",
      "title": "WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66571"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-86049",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter-server",
      "product": "jupyter_server",
      "cwe": "CWE-532",
      "title": "Jupyter Server: 5xx request logging leaks token-bearing Referer header values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86049"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-86862",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-88",
      "title": "pgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86862"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-90887",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Inventory",
      "product": "WP Inventory Manager",
      "cwe": "CWE-79",
      "title": "WordPress WP Inventory Manager plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90887"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-90986",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODEPRESS IT Solutions LLC",
      "product": "Visitor Traffic Real Time Statistics Pro",
      "cwe": "CWE-79",
      "title": "WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.21 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90986"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-92925",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Pen Drive Powered by Red Hat Lightspeed",
      "cwe": "CWE-125",
      "title": "Redis: redis: out-of-bounds read via crafted cluster bus packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92925"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-92959",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 before 3.11.8 allowAsync Bypass via Promise Thenable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92959"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-93014",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RosarioSIS",
      "product": "RosarioSIS",
      "cwe": "CWE-22",
      "title": "RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93014"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-45720",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siderolabs",
      "product": "omni",
      "cwe": "CWE-294",
      "title": "Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45720"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-93015",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlueKitchen GmbH",
      "product": "BTstack",
      "cwe": "CWE-787",
      "title": "BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93015"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-54633",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "podofo",
      "product": "podofo",
      "cwe": "CWE-125",
      "title": "PoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchScanLine)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54633"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-61793",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt-modules",
      "product": "og-image",
      "cwe": "CWE-20",
      "title": "Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61793"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-78223",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-347",
      "title": "Token revocation record built from unverified JWT claims in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78223"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-89038",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Verizon",
      "product": "Verizon Cloud for Android",
      "cwe": "CWE-22",
      "title": "Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89038"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-92915",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-770",
      "title": "WWBN AVideo userVerifyEmail.php Unauthenticated Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92915"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-92921",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cjbi",
      "product": "admin3",
      "cwe": "CWE-916",
      "title": "admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92921"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-92933",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-200",
      "title": "vm2 before 3.11.8 Information Disclosure via util.getCallSites",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92933"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-92936",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-209",
      "title": "vm2 3.11.0 before 3.11.7 Information Disclosure via Error Stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92936"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-92963",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-227",
      "title": "vm2 before 3.11.2 Information Disclosure via Internal State",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92963"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-93395",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "C Driver",
      "cwe": "CWE-191",
      "title": "Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93395"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-93451",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xerial",
      "product": "snappy-java",
      "cwe": "CWE-787",
      "title": "snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93451"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-81447",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-295",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81447"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-85717",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-200",
      "title": "AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85717"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-92756",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "MongoDB Entity Framework Core Provider",
      "cwe": "CWE-311",
      "title": "Combining encryption settings may disable encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92756"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-92757",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "MongoDB Entity Framework Core Provider",
      "cwe": "CWE-311",
      "title": "Malformed connection string may disable field level encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92757"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-44235",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alanxz",
      "product": "rabbitmq-c",
      "cwe": "CWE-125",
      "title": "rabbitmq-c: size_t underflow in AMQP frame length computation leads to out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44235"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-52852",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traccar",
      "product": "traccar",
      "cwe": "CWE-674",
      "title": "Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52852"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-54648",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cubecart",
      "product": "v6",
      "cwe": "CWE-862",
      "title": "CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Customer Data Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54648"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-54676",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erudika",
      "product": "scoold",
      "cwe": "CWE-862",
      "title": "Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal API tokens are enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54676"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-54677",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erudika",
      "product": "scoold",
      "cwe": "CWE-862",
      "title": "Scoold: Authenticated user can post replies and comments to private-space questions without space membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54677"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-66572",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetBlog",
      "cwe": "CWE-79",
      "title": "WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66572"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-66573",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetTabs",
      "cwe": "CWE-79",
      "title": "WordPress JetTabs plugin <= 2.3.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66573"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-66574",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Element Pack Elementor Addons",
      "cwe": "CWE-79",
      "title": "WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66574"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-66576",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetBlocks For Elementor",
      "cwe": "CWE-79",
      "title": "WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66576"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-66577",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetSearch",
      "cwe": "CWE-79",
      "title": "WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66577"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-66578",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Property Hive",
      "product": "PropertyHive",
      "cwe": "CWE-79",
      "title": "WordPress PropertyHive plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66578"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-66579",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetElements For Elementor",
      "cwe": "CWE-79",
      "title": "WordPress JetElements For Elementor plugin <= 2.9.2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66579"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-66617",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Series",
      "cwe": "CWE-79",
      "title": "WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66617"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-67071",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL DevOps Deploy / HCL Launch",
      "cwe": "CWE-212",
      "title": "HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or Transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67071"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-77281",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-94",
      "title": "Caddy: rewrite placeholder re-expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77281"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-78294",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dylan Kuhn",
      "product": "Geo Mashup",
      "cwe": "CWE-79",
      "title": "WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78294"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-81453",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-22",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81453"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-81868",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "security-advisories",
      "cwe": "CWE-288",
      "title": "Steeltoe: Header-forwarded client cert lacks proof of private-key possession",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81868"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-85078",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sanic-org",
      "product": "sanic",
      "cwe": "CWE-444",
      "title": "sanic chunked trailer request smuggling allows hidden second request execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85078"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-2585",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefusecom",
      "product": "Brizy – Page Builder",
      "cwe": "CWE-79",
      "title": "Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2585"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-66608",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-918",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.19 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66608"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-81443",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-918",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81443"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-86522",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-117",
      "title": "Log injection via an unescaped password reset identity in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86522"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-92949",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-471",
      "title": "vm2 3.9.6 before 3.11.7 Sandbox Bypass via Accessor Descriptor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92949"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-93394",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "C Driver",
      "cwe": "CWE-303",
      "title": "libmongoc SCRAM client nonce-validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93394"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-54521",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M66B",
      "product": "FairEmail",
      "cwe": "CWE-79",
      "title": "FairEmail: Cross-site scripting (XSS) in AMP message rendering (ActivityAMP)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54521"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-54644",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cubecart",
      "product": "v6",
      "cwe": "CWE-79",
      "title": "CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54644"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-55946",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Copilot",
      "cwe": "CWE-77",
      "title": "Microsoft Copilot Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55946"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-53556",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "SQLBot",
      "cwe": "CWE-89",
      "title": "SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53556"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-54582",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-73",
      "title": "mport package installation can overwrite existing unmanaged or differently owned files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54582"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-54585",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-22",
      "title": "mport sample file handling can write outside the configured root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54585"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-54586",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-319",
      "title": "mport permits repository and package mirror fetches over insecure transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54586"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-86861",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-59",
      "title": "pgAdmin 4: File Manager save_file writes through a symbolic link planted after the containment check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86861"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-75523",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "security-advisories",
      "cwe": "CWE-200",
      "title": "Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75523"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-85718",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-400",
      "title": "AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85718"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-85720",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-319",
      "title": "AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85720"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-50022",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NCEAS",
      "product": "metacat",
      "cwe": "CWE-441",
      "title": "Metacat acts as unintended proxy to backend Apache SOLR engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50022"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-54575",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-78",
      "title": "mport package fetch and clean paths are vulnerable to TOCTOU filesystem races",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54575"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-54576",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-59",
      "title": "mport package installation has symlink TOCTOU in chown and chmod handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54576"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-54587",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-59",
      "title": "mport directory asset installation is vulnerable to symlink and path traversal races",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54587"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-81479",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-187",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81479"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-92758",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "MongoDB Entity Framework Core Provider",
      "cwe": "CWE-532",
      "title": "Logs may collect sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92758"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-50291",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-125",
      "title": "OpenImageIO: Segmentation Fault in BmpInput::read_native_scanline (bmpinput.cpp:399)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50291"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-76781",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76781"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-92926",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Matrimonial System",
      "cwe": "CWE-74",
      "title": "code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92926"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-92927",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-200",
      "title": "SourceCodester Drug Recommendation System drug_recommendor.sql information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92927"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-14311",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "melograno",
      "product": "Booking for Appointments and Events Calendar – Amelia",
      "cwe": "CWE-862",
      "title": "Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14311"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-54613",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "givanz",
      "product": "Vvveb",
      "cwe": "CWE-22",
      "title": "Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54613"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-54643",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cubecart",
      "product": "v6",
      "cwe": "CWE-862",
      "title": "CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54643"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-73999",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gora Tech",
      "product": "Cooked",
      "cwe": "CWE-639",
      "title": "WordPress Cooked plugin <= 1.16.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73999"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-74005",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Series",
      "cwe": "CWE-352",
      "title": "WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74005"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-80355",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-352",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80355"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-8674",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-617",
      "title": "Assertion failure in the DNS stub resolver with a long search domain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8674"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-16582",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "melograno",
      "product": "Booking for Appointments and Events Calendar – Amelia",
      "cwe": "CWE-862",
      "title": "Booking for Appointments and Events Calendar - Amelia <= 2.4.5 - Missing Authorization to Unauthenticated Payment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16582"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-16750",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylemix",
      "product": "Motors – Car Dealership & Classified Listings Plugin",
      "cwe": "CWE-862",
      "title": "Motors – Car Dealership & Classified Listings <= 1.4.120 - Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16750"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-54355",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MapServer",
      "product": "MapServer",
      "cwe": "CWE-79",
      "title": "MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54355"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-54594",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OmniBlocks",
      "product": "monorepo",
      "cwe": "CWE-799",
      "title": "OmniBlocks: Spamming in Discussions tab possible via disc.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54594"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-54604",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openslide",
      "product": "openslide",
      "cwe": "CWE-758",
      "title": "OpenSlide: openslide_read_region() returns uninitialized memory with libtiff 4.7.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54604"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-54642",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cubecart",
      "product": "v6",
      "cwe": "CWE-352",
      "title": "CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54642"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-54907",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fuomag9",
      "product": "caddy-proxy-manager",
      "cwe": "CWE-1188",
      "title": "Caddy Proxy Manager: Registrations enabled by default allows creating users with \"user\" permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54907"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-54918",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netbox-community",
      "product": "devicetype-library",
      "cwe": "CWE-15",
      "title": "NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIBRARY_URL) enables SSRF and test-data substitution from CI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54918"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-63461",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vendurehq",
      "product": "vendure",
      "cwe": "CWE-200",
      "title": "Vendure: Shop API list queries can return non-public entities when filterOperator is OR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63461"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-66575",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KingAddons.com",
      "product": "King Addons for Elementor",
      "cwe": "CWE-639",
      "title": "WordPress King Addons for Elementor plugin <= 51.1.81 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66575"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-66676",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MatrixAddons",
      "product": "Easy Invoice",
      "cwe": "CWE-862",
      "title": "WordPress Easy Invoice plugin <= 2.3.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66676"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-71568",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openshift-metal3",
      "product": "bmctest",
      "cwe": "CWE-306",
      "title": "BMCtest exposes Ironic without authentication and TLS during the test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71568"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-74000",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Simple Membership",
      "cwe": "CWE-862",
      "title": "WordPress Simple Membership plugin <= 4.8.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74000"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-74002",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevelop",
      "product": "Booking Calendar",
      "cwe": "CWE-862",
      "title": "WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74002"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-74017",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "User Registration",
      "cwe": "CWE-862",
      "title": "WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74017"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-78296",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP ManageNinja LLC",
      "product": "FluentAuth",
      "cwe": "CWE-345",
      "title": "WordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78296"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-78528",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerqWP",
      "product": "BerqWP",
      "cwe": "CWE-862",
      "title": "WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78528"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-81829",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Exploit Intelligence",
      "cwe": "CWE-22",
      "title": "Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81829"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-85999",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facelessuser",
      "product": "soupsieve",
      "cwe": "CWE-400",
      "title": "Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85999"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-86000",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facelessuser",
      "product": "soupsieve",
      "cwe": "CWE-400",
      "title": "Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86000"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-92879",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-400",
      "title": "vgmstream mus_acm.c parse_mus resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92879"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-92880",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-119",
      "title": "vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92880"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-92881",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-369",
      "title": "vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92881"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-92920",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cjbi",
      "product": "admin3",
      "cwe": "CWE-613",
      "title": "admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92920"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-92973",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pycontribs",
      "product": "ansi2html",
      "cwe": "CWE-79",
      "title": "ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92973"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-93013",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infiniflow",
      "product": "ragflow",
      "cwe": "CWE-22",
      "title": "RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93013"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-93308",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "O-RAN-SC",
      "product": "SMO OAM",
      "cwe": "CWE-770",
      "title": "O-RAN-SC SMO OAM VES Collector allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93308"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-93309",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "O-RAN-SC",
      "product": "SMO OAM",
      "cwe": "CWE-770",
      "title": "O-RAN-SC SMO OAM VES Collector allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93309"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-53555",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "SQLBot",
      "cwe": "CWE-79",
      "title": "Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53555"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-92932",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "sachertortephp",
      "cwe": "CWE-670",
      "title": "MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF When readFile Is Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92932"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-93295",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-20",
      "title": "MISP Background Job Argument Injection via Console Path Switches Enables Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93295"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-93296",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-79",
      "title": "MISP Overmind: Stored Cross-Site Scripting via Unescaped Object Names in Statistics Legends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93296"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-93454",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Aureus ERP",
      "cwe": "CWE-79",
      "title": "Aureus ERP through 1.6.0 Stored XSS via Payment Term Note",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93454"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-54546",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfpc-coe",
      "product": "CloudTAK",
      "cwe": "CWE-918",
      "title": "CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54546"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-54645",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cubecart",
      "product": "v6",
      "cwe": "CWE-79",
      "title": "CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54645"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-92611",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Ankaios",
      "cwe": "CWE-863",
      "title": "In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92611"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-54565",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "edwardkim",
      "product": "rhwp",
      "cwe": "CWE-200",
      "title": "rhwp browser extension performs SSRF / private-network requests and leaks HWP preview data to untrusted pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54565"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-18441",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
      "cwe": "CWE-639",
      "title": "LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18441"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-54495",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-feature",
      "product": "open-feature-operator",
      "cwe": "CWE-668",
      "title": "Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54495"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-54551",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h44z",
      "product": "wg-portal",
      "cwe": "CWE-285",
      "title": "WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces' traffic stats to every user (missing per-user authorization)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54551"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-92893",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-863",
      "title": "Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92893"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-92894",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-863",
      "title": "Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92894"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-92904",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-863",
      "title": "Rubygem-foreman_remote_execution: job output readable without object-level view_job_invocations check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92904"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-81441",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-306",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81441"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-12284",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-346",
      "title": "Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12284"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-61700",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariadb-corporation",
      "product": "mariadb-connector-j",
      "cwe": "CWE-284",
      "title": "MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61700"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-81438",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-327",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81438"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-81439",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-863",
      "title": "Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81439"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-85716",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-287",
      "title": "AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85716"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-54471",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "SmartFabric Manager",
      "cwe": "CWE-280",
      "title": "Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54471"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-45723",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siderolabs",
      "product": "omni",
      "cwe": "CWE-20",
      "title": "Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45723"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-75588",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-1287",
      "title": "Mattermost Desktop App plugin popout scheme validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75588"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-54579",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-125",
      "title": "mport mirror-selection ping accepts insufficiently validated ICMP replies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54579"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-81637",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-613",
      "title": "Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81637"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-92945",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-22",
      "title": "vm2 before 3.11.7 Module Allowlist Bypass via Prefix Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92945"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-54649",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PunchIn-App",
      "product": "punchin-email",
      "cwe": "CWE-200",
      "title": "punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-To",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54649"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-92962",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.js",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92962"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-92992",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "mayfly-go",
      "cwe": "CWE-862",
      "title": "Dromara mayfly-go AI Assistant ai.go authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92992"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-92993",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "mayfly-go",
      "cwe": "CWE-77",
      "title": "Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92993"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-93307",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "O-RAN-SC",
      "product": "SMO OAM",
      "cwe": "CWE-400",
      "title": "O-RAN-SC SMO OAM VES Collector memory allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93307"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-54577",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-20",
      "title": "mport audit can inspect the wrong package when options are present",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54577"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-54578",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-354",
      "title": "mport verify can compare stale checksum data after hashing failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54578"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-82723",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-532",
      "title": "Actor record with password digest stored in AshAuthentication audit log entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82723"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-82759",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-760",
      "title": "Reversible IP address pseudonymisation in AshAuthentication audit log hash mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82759"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-55061",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uniget-org",
      "product": "cli",
      "cwe": "CWE-88",
      "title": "uniget: EDITOR Command Injection in uniget CLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55061"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-49292",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiwitcms",
      "product": "Kiwi",
      "cwe": "CWE-862",
      "title": "Kiwi TCMS: The /init-db/ page renders and responds to requests after first use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49292"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2021-3030",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component, executes arbitrary JavaScript in the security context of that site.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-3030"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2025-55787",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55787"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-52483",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request for the endpoint /cgi-bin/device-management-utilities-internet.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52483"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-73638",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Imager",
      "cwe": "CWE-125",
      "title": "Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73638"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-73639",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Imager-File-PNG",
      "cwe": "CWE-787",
      "title": "Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73639"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-90050",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: fq: clamp quantum and initial_quantum in change path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90050"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-90051",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: reject non zerocopy devmem tx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90051"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-90052",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-integrity: fix buffer overflow with keyed discard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90052"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-90053",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: sch_htb: limit htb_classify inner-class filter hops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90053"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-90054",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: fix corruption of urgent data on multi-segment retransmit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90054"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-90055",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: atm: usbatm: fix invalid ci_range initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90055"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-90056",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: fec: only stop PTP if it was initialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90056"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-90057",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90057"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-90058",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90058"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-90059",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: stmmac: restore NET_IP_ALIGN in the RX DMA offset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90059"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-90060",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: control: Don't add invalid kcontrols to LED layer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90060"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-90061",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_tables: skip double clone set expressions on element insert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90061"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-90062",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_tables: move hardware offload step after building the chain blob",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90062"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-90063",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio-net: Ensure that TCP packets don't overflow gso_segs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90063"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-90064",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe: Reject page faults from non-fault-mode scratch VMs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90064"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-90065",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90065"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-90066",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90066"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-90067",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "libceph: validate banner payload length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90067"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-90068",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: dapm: Fix off-by-one check on the second enum channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90068"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-90069",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: acomp - allocate async request context when cloning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90069"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-90070",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tpm: st33zp24: Return zero on status read failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90070"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-90071",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: sch_teql: restore skb->dev on the slave failure path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90071"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-90072",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: sfq: clamp quantum to avoid signed overflow soft lockup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90072"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-90073",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: hhf: clamp quantum before hhf_change() to avoid overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90073"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-90074",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: fq_pie: clamp default quantum to avoid signed overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90074"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-90075",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: fq_codel: clamp default quantum and mtu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90075"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-90076",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: fq: add overflow bounds to quantum and initial quantum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90076"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-90077",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: fix a resource leak in copy_net_ns() error handling path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90077"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-90078",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: act_skbmod: fix length calculations and avoid invalid header warnings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90078"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-90079",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90079"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-90080",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90080"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-90081",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: use wq_has_sleeper() in rds_cong_map_updated()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90081"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-90082",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mana: Cap MSI-X vectors to the device MSI-X table size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90082"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-90083",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: act_ife: Only operate on Ethernet frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90083"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-90084",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-vf: fix workqueue and netdev race in probe/remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90084"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-90085",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-af: fix NULL deref in NIX TM tree debugfs read path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90085"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-90086",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xsk: honor XDP_TX_METADATA in zero-copy path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90086"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-90087",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: do not leak an hci_conn when a second LE connect is rejected",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90087"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-90088",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90088"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-90089",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btnxpuart: Validate the FW dump header length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90089"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-90090",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90090"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-90091",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90091"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-90092",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90092"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-90093",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: access chan->conn safely in get/setsockopt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90093"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-90094",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: process: Fix context switching MTE store-only tag check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90094"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-90095",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: Fix the condition to enable over-io-uring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90095"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-90096",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: invalidate the correct range after O_APPEND direct write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90096"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-90097",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90097"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-90098",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: sparx5: fix sleep in atomic context in MAC table access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90098"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-90099",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: account classifier filter allocations to memcg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90099"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-90100",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ptp: netc: fix period truncation and potential divide-by-zero in PEROUT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90100"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-90101",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bnxt_en: Fix call to hardware monitoring event handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90101"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-90102",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4/pnfs: key the data server cache on the NFS version",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90102"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-90103",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4.2: fix LAYOUTSTATS send buffer exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90103"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-90104",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4.1: zero referring call lists before decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90104"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-90105",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: fix reading neigh ha",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90105"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-90106",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: arp/nd proxy: fix reading neigh ha",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90106"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-90107",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: free pending qentry in smc_llc_flow_stop() before memset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90107"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-90108",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90108"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-90109",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90109"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-90110",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "inetpeer: randomize RB-tree node comparison using SipHash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90110"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-90111",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ip6mr: do not clone dst in ip6mr_cache_report()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90111"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-90112",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: qlcnic: validate unified ROM sections before loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90112"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-90113",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netdevsim: update queue NAPI association on queue reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90113"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-90114",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: Reject descending VLAN tunnel ranges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90114"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-90115",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xsk: fix NULL pointer dereference in __xsk_rcv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90115"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-90116",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: mtpav: shut down output timer before card teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90116"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-90117",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: validate usa_ofs before preserving the update sequence number",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90117"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-90118",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: fix off-by-one page overflow in ntfs_decompress()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90118"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-90119",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90119"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-90120",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "irqchip/gic-v5: Check get_logical_index() return value in MADT IAFFID parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90120"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-90121",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "irqchip/gic-v5: Clear per-CPU IRS data on teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90121"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-90122",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: visconti: Make sure clk_init_data is fully initialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90122"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-90123",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "irqchip/ast2700-intc: Avoid allocating in the irq_domain activate() callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90123"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-90124",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "irqchip/renesas-rzg2l: Fix loss of interrupt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90124"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-90125",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix request buffer leak in smb2_new_read_req()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90125"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-90126",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rtc: pcf8563: fix clock provider leak on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90126"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-90127",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio: rtc: time out alarm requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90127"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-90128",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vdpa/mlx5: fix wrong list iterated in add_direct_chain error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90128"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-90129",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio_balloon: quiesce balloon work before device shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90129"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-90130",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vdpa_sim: fix cleanup after worker creation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90130"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-90131",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: serialize resident iomap reads with mrec_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90131"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-90132",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: reject unprivileged writes to reserved $LX* xattrs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90132"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-90133",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90133"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-90134",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs: fix kmap_local_page() usage in compress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90134"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-90135",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90135"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-90136",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86/amd/hsmp: Reject negative power cap writes in hwmon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90136"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-90137",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: hp-bioscfg: fix password encoding bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90137"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-90138",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vsock: don't check the listener's sk_err in vsock_accept()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90138"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-90139",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: check for NULL root inode in fuse_fill_super_submount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90139"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-90140",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cuse: wait for pending RCU callbacks on module exit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90140"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-90141",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: fix integer overflow in ftp helper port/address parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90141"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-90142",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio_net: Fix resize of the RX ring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90142"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-90143",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: kcm: Hold RCU read lock while running BPF parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90143"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-90144",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dpll: fix NULL deref in dpll_device_ops() during teardown race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90144"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-90145",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90145"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-90146",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, xdp: move offload check into dev_xdp_install()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90146"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-90147",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90147"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-90148",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90148"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-90149",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90149"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-90150",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pnfs/blocklayout: Fix device leaks on parse failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90150"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-90151",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSv4: remove callback IDR entry on client allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90151"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-90152",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/server: fix session leak in ksmbd_session_register()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90152"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-90153",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90153"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-90154",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: scope session state changes to bound connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90154"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-90155",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: detach blocked lock requests before freeing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90155"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-90156",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: safely discard unregistered deferred locks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90156"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-90157",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject negative optlen in cgroup getsockopt hook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90157"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-90158",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "m68k: nfcon: Do not call console_is_registered() in nfcon_device()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90158"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-90159",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90159"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-90160",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "lwt_bpf: Restore reserved headroom after xmit program",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90160"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-90161",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: fix interlaced ztailpacking pclusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90161"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-90162",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: defer publishing granted locks to prevent UAF/double-free race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90162"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-90163",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/server: call ksmbd_proc_cleanup() on module init failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90163"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-90164",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/server: abort initialization when proc setup fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90164"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-90165",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90165"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-90166",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90166"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-90167",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: serialize oplock close with pending break ownership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90167"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-90168",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: retain connection for pending notify work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90168"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-90169",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: free preauth sessions on connection teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90169"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-90170",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: validate ipc response length before dereferencing its fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90170"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-90171",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: smbdirect: release pending child sockets outside the handler lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90171"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-90172",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: smbdirect: destroy QP before mem pools on accept failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90172"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-90173",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: smbdirect: free completion queues with ib_free_cq()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90173"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-90174",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_user()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90174"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-90175",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90175"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-90176",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: Do not skip lock checks for single-byte ranges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90176"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-90177",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Check pointer type for all atomic RMW paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90177"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-90178",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (coretemp) Fix core_data leak on CPUs without PTS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90178"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-90179",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: fix deadlock in complain-mode change_hat",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90179"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-90180",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: mtip32xx: synchronize ioctls with device removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90180"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-90181",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: avoid teardown retry loop on xarray allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90181"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-90182",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "blk-iocost: clear delay state when freeing policy data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90182"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-90183",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "blk-iolatency: clear delay state when freeing policy data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90183"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-90184",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "null_blk: serialize configfs attribute updates with device setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90184"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-90185",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "null_blk: serialize configfs attribute stores with the lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90185"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-90186",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "null_blk: reject per-device queue resize for shared tag set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90186"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-90187",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "null_blk: free zones array on device power-off",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90187"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-90188",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "null_blk: free global tag_set on init error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90188"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-90189",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "null_blk: register configfs subsystem after creating default devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90189"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-90190",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "null_blk: use DEFINE_MUTEX for the file-scope mutex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90190"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-90191",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mailbox: riscv-sbi-mpxy: validate RPMI notification lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90191"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-90192",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mailbox: qcom-cpucp: handle NULL data in send_data callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90192"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-90193",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90193"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-90194",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: scan: fix bus ID cleanup on device_add() failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90194"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-90195",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90195"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-90196",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: SOF: validate topology volume range before allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90196"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-90197",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: haptic: don't write an uninitialized value to unhandled usages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90197"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-90198",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: core: Fix use-after-free in snd_card_do_free()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90198"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-90199",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: reject out-of-range evcn in mi_enum_attr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90199"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-90200",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: fix integer overflow in MFT cluster validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90200"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-90201",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90201"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-90202",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90202"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-90203",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Squashfs: check block offset is not negative",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90203"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-90204",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: validate DIO orphan slot during inode read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90204"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-90205",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: validate orphan slot during inode read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90205"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-90206",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: fix max_qid race between configfs and controller allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90206"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-90207",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: seq: midi: Serialize input teardown with event_input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90207"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-90208",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clocksource/drivers/samsung_pwm: Switch to raw_spinlock_t type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90208"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-90209",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/debug: Fix deadlock during unregister",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90209"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-90210",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90210"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-90211",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, s390: Clear fetch destination on faulting arena atomic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90211"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-90212",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64/efi: Avoid voluntary preemption with efi_mm installed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90212"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-90213",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firewire: core: fix memory leak in error path of build_tree()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90213"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-90214",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: xilinx: formatter_pcm: fix stream_data leak on open error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90214"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-90215",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: ubi: Release device reference on busy detach",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90215"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-90216",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ubi: Fix rollback for explicit UBI device numbers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90216"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-90217",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Compare iterator types during state pruning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90217"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-90218",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/cma: Fix WARNING in res_to_rt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90218"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-90219",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/cxgb4: Free debugfs on registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90219"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-90220",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: seq: Don't leak the extension cell pointer in the bounce payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90220"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-90221",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90221"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-90222",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: pn533: hold a reference to the request skb during send_frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90222"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-90223",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: llcp: bound SNL TLV parsing to the skb and add length checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90223"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-90224",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: nci: fix double completion race in nci_data_exchange_complete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90224"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-90225",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: llcp: read llcp_sock->local under the socket lock in getsockopt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90225"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-90226",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfc: llcp: avoid userspace overflow on invalid optlen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90226"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-90227",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90227"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-90228",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90228"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-90229",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-apple: Destroy the admin queue on removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90229"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-90230",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90230"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-90231",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: fix unconfined user namespace restriction forced stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90231"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-90232",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "amt: Don't support cross-netns setup.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90232"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-90233",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-pci: release descriptor pools on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90233"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-90234",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFS: Return a delegation the client fails to record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90234"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-90235",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90235"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-90236",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: Release the export reference when reaping open stateids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90236"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-90237",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nft_ct: move custom expectation support to helper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90237"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-90238",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90238"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-90239",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90239"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-90240",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Flush context cache with correct SID when tearing down aliases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90240"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-90241",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Tear down scalable-mode context on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90241"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-90242",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Fix iopf_refcount leak on RID domain replacement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90242"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-90243",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Clear Present bit before tearing down copied context entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90243"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-90244",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/dma: Restore locking around msi_page_list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90244"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-90245",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbdev: kyro: Validate overlay viewport coordinates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90245"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-90246",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: fix integer overflow in verify_tags() bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90246"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-90247",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix mmap_lock leak in irq_work path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90247"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-90248",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_api: fix teardown of an adopted proto on insert-race loss",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90248"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-90249",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90249"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-90250",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, cgroup: Fix storage null-ptr-deref after replacing prog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90250"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-90251",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: MSFT: validate evt_prefix_len against the response length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90251"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-90252",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: MGMT: free the HCI command when it is cancelled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90252"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-90253",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: MGMT: free the mesh send cancel command when it is cancelled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90253"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-90254",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90254"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-90255",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_conn: fix the SCO setup context lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90255"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-90256",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90256"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-90257",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: virtio_bt: avoid OOB read of build info string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90257"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-90258",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: airoha: add missed IRQ resource helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90258"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-90259",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90259"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-90260",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: zoned: don't clobber the extent buffer when zeroing it out",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90260"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-90261",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: zoned: flush active metadata block group at btree_writepages() start",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90261"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-90262",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: retry verity reads for not-uptodate Merkle folios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90262"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-90263",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: check if root is readonly when setting posix acl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90263"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-90264",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: always wait for ordered extents to avoid OE races",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90264"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-90265",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: defrag: fix deadlock between defrag and delalloc space reservation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90265"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-90266",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: zoned: don't force read-only on transient -EAGAIN from reloc merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90266"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-90267",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90267"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-90268",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: sd: Fix error handling in sd_probe() after large pool creation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90268"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-90269",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject load-acquire from pointers requiring fault protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90269"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-90270",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm_mpam: Disable driver unbind to avoid UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90270"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-90271",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90271"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-90272",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf: arm_pmuv3: Zero initialize hw_id branch stack field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90272"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-90273",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90273"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-90274",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "coresight: etm4x: fix underflow for usage of (nrseqstate - 1)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90274"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-90275",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/raid1: don't set array_frozen in raid1_takeover()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90275"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-90276",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/md-llbitmap: stop daemon timer rearm on destroy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90276"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-90277",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/md-llbitmap: prevent create failure bitmap UAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90277"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-90278",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md: wait for behind writes before destroying bitmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90278"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-90279",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/raid5: round bitmap stripes with sector division",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90279"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-90280",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90280"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-90281",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90281"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-90282",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90282"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-90283",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hugetlbfs: release subpool on fill_super failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90283"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-90284",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware_loader: do not queue completed sysfs fallback requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90284"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-90285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90285"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-90286",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/gfx6: Use PFP on the compute queues too",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90286"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-90287",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: sunplus: fix error handling in sp_uphy_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90287"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-90288",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90288"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-90289",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Resize MST HDCP per-connector arrays to 32",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90289"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-90290",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: hibernate: Restore DAIF state on error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90290"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-90291",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "module/dups: Fix use-after-free in kmod_dup_req lifetime handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90291"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-90292",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/siw: Fix use-after-free in siw_accept()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90292"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-90293",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/isert: post the full-feature receive buffers after session registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90293"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-90294",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/isert: delay the final Login Response until the session is registered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90294"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-90295",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: imx6q: fix out-of-bounds write when probed more than once",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90295"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-90296",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: imx6q: fix devres accumulation across driver rebind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90296"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-90297",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/sun4i: crtc: Propagate layer initialization error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90297"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-90298",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/sun4i: tcon: Drop TCON TOP device reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90298"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-90299",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix sleepable check for tracing/lsm prog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90299"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-90300",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Clear buf on error in __bpf_get_task_stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90300"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-90301",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: o2hb: quiesce negotiate handlers and timeout work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90301"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-90302",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: synchronize heartbeat callbacks with o2net teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90302"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-90303",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90303"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-90304",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ARM: 9484/1: enable interrupts when unhandled user faults are triggered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90304"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-90305",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90305"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-90306",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ARM: 9481/2: breakpoint: CFI breakpoints only on demand",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90306"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-90307",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90307"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-90308",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/erdma: Hold QP references for AE and CM processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90308"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-90309",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/erdma: Hold CQ references when processing EQ events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90309"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-90310",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xen/xenbus: check otherend_id only after it has been initialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90310"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-90311",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thermal: hwmon: Remove hwmon class device along with its parent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90311"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-90312",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Check load-acquire src ptr type before the load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90312"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-90313",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90313"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-90314",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90314"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-90315",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90315"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-90316",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/omap: dsi: Do not copy isr table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90316"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-90317",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Invalidate RCU pointers after final spin unlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90317"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-90318",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fat: release buffer head after rebuilding parent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90318"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-90319",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rapidio: clear mport->net when rio_add_net() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90319"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-90320",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: validate external xattr entries when reading metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90320"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-90321",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: validate inline xattrs during inode block validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90321"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-90322",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2/cluster: keep heartbeat local node stable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90322"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-90323",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: validate auto buf reg before taking uring_cmd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90323"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-90324",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: check import_ubuf() return value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90324"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-90325",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "blk-cgroup: skip dying blkg in blkcg_activate_policy()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90325"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-90326",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "blk-cgroup: fix race between policy activation and blkg destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90326"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-90327",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phonet: pep: do not write beyond optlen in getsockopt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90327"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-90328",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: steam: Reject short reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90328"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-90329",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: synchronize input before cleaning up a failed probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90329"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-90330",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: logitech-hidpp: Fix FF device cleanup on init failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90330"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-90331",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: asus: refactor the two workqueues and init sequence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90331"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-90332",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: dwc: ep: Flush cached MSI write before unmapping the iATU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90332"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-90333",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-integrity: replace forgeable discard filler with a keyed sector marker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90333"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-90334",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tty: clear cdev pointer after cdev_add() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90334"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-90335",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tty: skip cdev_del() when no cdev is registered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90335"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-90336",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: core: clear freed pointers on uart_register_driver() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90336"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-90337",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: core: do fallible allocations before the console can be registered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90337"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-90338",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: amba-pl011: keep console clock enabled for atomic writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90338"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-90339",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/syscall: Fix syscall skip handling for seccomp and ptrace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90339"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-90340",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: generic: free maps on pinctrl_generic_to_map() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90340"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-90341",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: coreboot: Validate table bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90341"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-90342",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix mmap_lock deadlock on arena lock failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90342"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-90343",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: stop PMSR before P2P and NAN teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90343"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-90344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: disconnect on CSA to channel 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90344"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-90345",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: brcmfmac: fix P2P action frame handling without device vif",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90345"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-90346",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: nl80211: clean up color-change beacon data on errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90346"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-90347",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90347"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-90348",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90348"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-90349",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90349"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-90350",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: reject out-of-range link ids in mt76_vif_link()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90350"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-90351",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90351"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-90352",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: release hif2 reference on probe IRQ failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90352"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-90353",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: fix ext PHY use-after-free on register error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90353"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-90354",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: fix double hif2 init on the non-WED path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90354"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-90355",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: clear stale link state on full reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90355"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-90356",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90356"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-90357",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90357"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-90358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, x86: Fix trampoline stack size for 128-bit arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90358"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-90359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject >8 byte return values on return-reading trampoline paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90359"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-90360",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "regulator: core: use system_freezable_wq for init complete work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90360"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-90361",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: fix leak in ath11k_service_ready_ext_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90361"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-90362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm/dsi: Drop dev_pm_opp_set_rate(0)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90362"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-90363",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm: don't tear down KMS twice when KMS init fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90363"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-90364",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: processor: Unregister cpufreq notifier on init failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90364"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-90365",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: cancel reset and rc work on device unregister",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90365"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-90366",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90366"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-90367",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90367"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-90368",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: unwind state on add_interface failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90368"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-90369",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: fix out-of-bounds access in mmio copy helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90369"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-90370",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90370"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-90371",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: fix RXDMAD_C buffer recycling race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90371"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-90372",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90372"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2026-90373",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90373"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2026-90374",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90374"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2026-90375",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: fix non-AQL packet accounting for MLO stations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90375"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-90376",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90376"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-90377",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: fix RX data queuing of RRO 3.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90377"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-90378",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt792x: Fix memory leak in SDIO TX path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90378"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-90379",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90379"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-90380",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90380"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-90381",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90381"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-90382",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90382"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-90383",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "misc: sgi-gru: remove interrupt-context page-table walks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90383"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-90384",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iomap: release the folio batch on iomap callback failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90384"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-90385",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/raid1: create serial pool adding rdev to array with serialize_policy=1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90385"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-90386",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90386"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-90387",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "swiotlb: Preserve allocation virtual address for dynamic pools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90387"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-90388",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/dma: Check atomic pool allocation result directly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90388"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-90389",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md: scope memalloc_noio to allocation critical sections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90389"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-90390",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/bitmap: resume array on backlog_store() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90390"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-90391",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90391"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-90392",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix potential UAF when reading bpf link info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90392"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-90393",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix potential UAF in bpf_netns_link_update_prog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90393"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-90394",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: sc2731_charger: cancel work on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90394"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-90395",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "power: supply: isp1704_charger: cancel work on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90395"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-90396",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: fix dio leak on metadata mapping error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90396"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-90397",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90397"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-90398",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90398"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-90399",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90399"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-90400",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md: recheck spare changes before starting sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90400"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-90401",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md: remove REQ_NOWAIT support from raid1/10/456",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90401"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-90402",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bus: mhi: host: Fix controller cleanup on EDL sysfs failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90402"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-90403",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtlwifi: pci: fix error path in rtl_pci_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90403"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-90404",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/chrome: cros_ec_debugfs: Unregister panic notifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90404"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-90405",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: stm32: dcmi: fix some error handling bugs in probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90405"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-90406",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: qcom: iris: handle runtime PM resume failure in core deinit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90406"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-90407",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90407"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-90408",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90408"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-90409",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/panthor: Add vm_bind region with kbo range overlap check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90409"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-90410",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: davinci: switch to managed controller allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90410"
    },
    {
      "rank": 778,
      "cve_id": "CVE-2026-90411",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90411"
    },
    {
      "rank": 779,
      "cve_id": "CVE-2026-90412",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: fix return status of RMI log page on allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90412"
    },
    {
      "rank": 780,
      "cve_id": "CVE-2026-90413",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/isert: reject login PDUs declaring more data than was received",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90413"
    },
    {
      "rank": 781,
      "cve_id": "CVE-2026-90414",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "IB/isert: reject PDUs declaring more data than was received",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90414"
    },
    {
      "rank": 782,
      "cve_id": "CVE-2026-90415",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/cxgb4: free STAG index when TPT entry write fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90415"
    },
    {
      "rank": 783,
      "cve_id": "CVE-2026-90416",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90416"
    },
    {
      "rank": 784,
      "cve_id": "CVE-2026-90417",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/cxgb4: Fix dereg_skb leak and double free in write_tpt_entry()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90417"
    },
    {
      "rank": 785,
      "cve_id": "CVE-2026-90418",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90418"
    },
    {
      "rank": 786,
      "cve_id": "CVE-2026-90419",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nilfs2: prevent out-of-bounds read in super root block parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90419"
    },
    {
      "rank": 787,
      "cve_id": "CVE-2026-90420",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nilfs2: fix infinite loop in nilfs_clean_segments()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90420"
    },
    {
      "rank": 788,
      "cve_id": "CVE-2026-90421",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: Fix UAF when probe runs concurrent to dyn ID removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90421"
    },
    {
      "rank": 789,
      "cve_id": "CVE-2026-90422",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90422"
    },
    {
      "rank": 790,
      "cve_id": "CVE-2026-90423",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Fix UAF in ODP init error-handling path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90423"
    },
    {
      "rank": 791,
      "cve_id": "CVE-2026-90424",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90424"
    },
    {
      "rank": 792,
      "cve_id": "CVE-2026-90425",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90425"
    },
    {
      "rank": 793,
      "cve_id": "CVE-2026-90426",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90426"
    },
    {
      "rank": 794,
      "cve_id": "CVE-2026-90427",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90427"
    },
    {
      "rank": 795,
      "cve_id": "CVE-2026-90428",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90428"
    },
    {
      "rank": 796,
      "cve_id": "CVE-2026-90429",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90429"
    },
    {
      "rank": 797,
      "cve_id": "CVE-2026-90430",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90430"
    },
    {
      "rank": 798,
      "cve_id": "CVE-2026-90431",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "remoteproc: Prevent crash handling to race with rproc_del()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90431"
    },
    {
      "rank": 799,
      "cve_id": "CVE-2026-90432",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Abort directly from the hardlockup handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90432"
    },
    {
      "rank": 800,
      "cve_id": "CVE-2026-90433",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: oc-tiny: switch to managed controller allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90433"
    },
    {
      "rank": 801,
      "cve_id": "CVE-2026-90434",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "isofs: release zisofs block pointer buffer head",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90434"
    },
    {
      "rank": 802,
      "cve_id": "CVE-2026-90435",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mlx5: Fix integer overflow of user QP buffer size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90435"
    },
    {
      "rank": 803,
      "cve_id": "CVE-2026-92230",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Karaf",
      "cwe": "CWE-401",
      "title": "Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92230"
    },
    {
      "rank": 804,
      "cve_id": "CVE-2026-92476",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: keembay - Initialize completion before requesting IRQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92476"
    },
    {
      "rank": 805,
      "cve_id": "CVE-2026-92477",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: ufs: debugfs: Reserve space for a string terminator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92477"
    },
    {
      "rank": 806,
      "cve_id": "CVE-2026-92478",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: ufs: core: Validate connected lane counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92478"
    },
    {
      "rank": 807,
      "cve_id": "CVE-2026-92479",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92479"
    },
    {
      "rank": 808,
      "cve_id": "CVE-2026-92480",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: ufs: core: Validate string descriptors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92480"
    },
    {
      "rank": 809,
      "cve_id": "CVE-2026-92481",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: mediatek: free EINT resources on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92481"
    },
    {
      "rank": 810,
      "cve_id": "CVE-2026-92482",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92482"
    },
    {
      "rank": 811,
      "cve_id": "CVE-2026-92483",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "liveupdate: Remember FLB retrieve() status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92483"
    },
    {
      "rank": 812,
      "cve_id": "CVE-2026-92484",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/region: Fix use-after-free in find_pos_and_ways() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92484"
    },
    {
      "rank": 813,
      "cve_id": "CVE-2026-92485",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix WARNING in bpf_tracing_link_release",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92485"
    },
    {
      "rank": 814,
      "cve_id": "CVE-2026-92486",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix CFI mismatch in task work callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92486"
    },
    {
      "rank": 815,
      "cve_id": "CVE-2026-92487",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "exfat: fix valid_size extension over a shared writable mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92487"
    },
    {
      "rank": 816,
      "cve_id": "CVE-2026-92488",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/erdma: complete object teardown when the destroy command fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92488"
    },
    {
      "rank": 817,
      "cve_id": "CVE-2026-92489",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: Fix skb double-free in xfrm_dev_direct_output()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92489"
    },
    {
      "rank": 818,
      "cve_id": "CVE-2026-92490",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Unrequest devices if driver registration fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92490"
    },
    {
      "rank": 819,
      "cve_id": "CVE-2026-92491",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Roll back partial protocol table registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92491"
    },
    {
      "rank": 820,
      "cve_id": "CVE-2026-92492",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92492"
    },
    {
      "rank": 821,
      "cve_id": "CVE-2026-92493",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92493"
    },
    {
      "rank": 822,
      "cve_id": "CVE-2026-92494",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: fix buffer_head leak in ext4_init_orphan_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92494"
    },
    {
      "rank": 823,
      "cve_id": "CVE-2026-92495",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92495"
    },
    {
      "rank": 824,
      "cve_id": "CVE-2026-92496",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92496"
    },
    {
      "rank": 825,
      "cve_id": "CVE-2026-92497",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92497"
    },
    {
      "rank": 826,
      "cve_id": "CVE-2026-92498",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath6kl: avoid buffer overreads in WMI event handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92498"
    },
    {
      "rank": 827,
      "cve_id": "CVE-2026-92499",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: validate readdir offset before accessing dirent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92499"
    },
    {
      "rank": 828,
      "cve_id": "CVE-2026-92500",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: use fsdata to track inline data write state and fix race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92500"
    },
    {
      "rank": 829,
      "cve_id": "CVE-2026-92501",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: drain in-flight DIO before buffered write fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92501"
    },
    {
      "rank": 830,
      "cve_id": "CVE-2026-92502",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: clear stale xarray tags on folios skipped during writeback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92502"
    },
    {
      "rank": 831,
      "cve_id": "CVE-2026-92503",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: fix ABBA deadlock in ext4_xattr_inode_cache_find()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92503"
    },
    {
      "rank": 832,
      "cve_id": "CVE-2026-92504",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thermal: intel: int3400: clean up ODVP on probe failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92504"
    },
    {
      "rank": 833,
      "cve_id": "CVE-2026-92505",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Fix undefined behavior in devid_write debugfs function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92505"
    },
    {
      "rank": 834,
      "cve_id": "CVE-2026-92506",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Fix requested device removal race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92506"
    },
    {
      "rank": 835,
      "cve_id": "CVE-2026-92507",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Fix potential use after free in ib_dealloc_pd_user()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92507"
    },
    {
      "rank": 836,
      "cve_id": "CVE-2026-92508",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Fix potential use after free in ib_free_cq()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92508"
    },
    {
      "rank": 837,
      "cve_id": "CVE-2026-92509",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Fix potential use after free in counter_release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92509"
    },
    {
      "rank": 838,
      "cve_id": "CVE-2026-92510",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Fix potential use after free in ib_destroy_srq_user()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92510"
    },
    {
      "rank": 839,
      "cve_id": "CVE-2026-92511",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Fix potential use after free in ib_destroy_cq_user()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92511"
    },
    {
      "rank": 840,
      "cve_id": "CVE-2026-92512",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Fix use after free in ib_query_qp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92512"
    },
    {
      "rank": 841,
      "cve_id": "CVE-2026-92513",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mana_ib: drain QP references after partial table insertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92513"
    },
    {
      "rank": 842,
      "cve_id": "CVE-2026-92514",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/erdma: Fix CEQ tasklet use-after-free on removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92514"
    },
    {
      "rank": 843,
      "cve_id": "CVE-2026-92515",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Preserve unique-field state across nested structs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92515"
    },
    {
      "rank": 844,
      "cve_id": "CVE-2026-92516",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix offset warn check for bpf_res_spin_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92516"
    },
    {
      "rank": 845,
      "cve_id": "CVE-2026-92517",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, riscv: Fix extable handling for arena load_acquire",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92517"
    },
    {
      "rank": 846,
      "cve_id": "CVE-2026-92518",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv, bpf: Fix kernel stack corruption in tailcall with CFI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92518"
    },
    {
      "rank": 847,
      "cve_id": "CVE-2026-92519",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv, bpf: Fix memory leak in bpf_jit_free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92519"
    },
    {
      "rank": 848,
      "cve_id": "CVE-2026-92520",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Zero queue and stack outputs on lock failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92520"
    },
    {
      "rank": 849,
      "cve_id": "CVE-2026-92521",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92521"
    },
    {
      "rank": 850,
      "cve_id": "CVE-2026-92522",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: processor: validate MADT IOAPIC entry bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92522"
    },
    {
      "rank": 851,
      "cve_id": "CVE-2026-92523",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/nldev: validate dynamic counter attribute length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92523"
    },
    {
      "rank": 852,
      "cve_id": "CVE-2026-92524",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92524"
    },
    {
      "rank": 853,
      "cve_id": "CVE-2026-92525",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92525"
    },
    {
      "rank": 854,
      "cve_id": "CVE-2026-93037",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/hfi1: Propagate sdma_txinit_ahg() errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93037"
    },
    {
      "rank": 855,
      "cve_id": "CVE-2026-93038",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: dac: ad5686: missing NULL check on match data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93038"
    },
    {
      "rank": 856,
      "cve_id": "CVE-2026-93039",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: meson: Keep link pointers valid on realloc failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93039"
    },
    {
      "rank": 857,
      "cve_id": "CVE-2026-93040",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: dw-edma: Serialize channel state checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93040"
    },
    {
      "rank": 858,
      "cve_id": "CVE-2026-93041",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: dw-edma: Serialize abort state updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93041"
    },
    {
      "rank": 859,
      "cve_id": "CVE-2026-93042",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: dw-edma: Terminate all descriptors without callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93042"
    },
    {
      "rank": 860,
      "cve_id": "CVE-2026-93043",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Disallow interpreter fallback for gotox insn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93043"
    },
    {
      "rank": 861,
      "cve_id": "CVE-2026-93044",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Disallow interpreter fallback for arena-related insns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93044"
    },
    {
      "rank": 862,
      "cve_id": "CVE-2026-93045",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject arena frees below the arena base",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93045"
    },
    {
      "rank": 863,
      "cve_id": "CVE-2026-93046",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "software node: Fix software_node_get_reference_args() with index -1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93046"
    },
    {
      "rank": 864,
      "cve_id": "CVE-2026-93047",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/v3d: Associate BOs with every job that accesses them",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93047"
    },
    {
      "rank": 865,
      "cve_id": "CVE-2026-93048",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93048"
    },
    {
      "rank": 866,
      "cve_id": "CVE-2026-93049",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mtd: mtdswap: Avoid freeing registered blktrans device twice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93049"
    },
    {
      "rank": 867,
      "cve_id": "CVE-2026-93050",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93050"
    },
    {
      "rank": 868,
      "cve_id": "CVE-2026-93051",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "misc: ad525x_dpot: use driver core groups for sysfs files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93051"
    },
    {
      "rank": 869,
      "cve_id": "CVE-2026-93052",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "misc: bcm-vk: Use acquire/release for msgq_inited",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93052"
    },
    {
      "rank": 870,
      "cve_id": "CVE-2026-93053",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "speakup: keyhelp: guard letter_offsets possible out-of-range indexing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93053"
    },
    {
      "rank": 871,
      "cve_id": "CVE-2026-93054",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "uio: Fix stale info pointer in failed registration path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93054"
    },
    {
      "rank": 872,
      "cve_id": "CVE-2026-93055",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "UDF symlink pathComponent header OOB read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93055"
    },
    {
      "rank": 873,
      "cve_id": "CVE-2026-93056",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_uac1_legacy: remove broken string configfs attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93056"
    },
    {
      "rank": 874,
      "cve_id": "CVE-2026-93057",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93057"
    },
    {
      "rank": 875,
      "cve_id": "CVE-2026-93058",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm: Only fini scheduler after successful init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93058"
    },
    {
      "rank": 876,
      "cve_id": "CVE-2026-93059",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm: Fix task_struct reference leak in recover_worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93059"
    },
    {
      "rank": 877,
      "cve_id": "CVE-2026-93060",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93060"
    },
    {
      "rank": 878,
      "cve_id": "CVE-2026-93061",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gpu: host1x: Avoid stack over-read in debug output helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93061"
    },
    {
      "rank": 879,
      "cve_id": "CVE-2026-93062",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93062"
    },
    {
      "rank": 880,
      "cve_id": "CVE-2026-93063",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mei: check SAP message length before reading it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93063"
    },
    {
      "rank": 881,
      "cve_id": "CVE-2026-93064",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93064"
    },
    {
      "rank": 882,
      "cve_id": "CVE-2026-93065",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93065"
    },
    {
      "rank": 883,
      "cve_id": "CVE-2026-93066",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/mm/pat: Take cpa_lock around large-page collapse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93066"
    },
    {
      "rank": 884,
      "cve_id": "CVE-2026-93067",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/bridge: tc358767: clamp the reported AUX read size to the request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93067"
    },
    {
      "rank": 885,
      "cve_id": "CVE-2026-93068",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Fix DM I2C teardown race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93068"
    },
    {
      "rank": 886,
      "cve_id": "CVE-2026-93069",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "OPP: Fix cleanup ordering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93069"
    },
    {
      "rank": 887,
      "cve_id": "CVE-2026-93070",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: ipu6: Do not free aux device pdata after init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93070"
    },
    {
      "rank": 888,
      "cve_id": "CVE-2026-93071",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: bcm2835-unicam: Fix asc leaked in error/remove path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93071"
    },
    {
      "rank": 889,
      "cve_id": "CVE-2026-93072",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "irqchip/renesas-irqc: Fix generic interrupt chip leak on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93072"
    },
    {
      "rank": 890,
      "cve_id": "CVE-2026-93073",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dax: read holder_ops once in dax_holder_notify_failure()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93073"
    },
    {
      "rank": 891,
      "cve_id": "CVE-2026-93074",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dax/fsdev: use __va(phys) for kaddr in direct_access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93074"
    },
    {
      "rank": 892,
      "cve_id": "CVE-2026-93075",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dax/fsdev: clear pgmap ops and owner on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93075"
    },
    {
      "rank": 893,
      "cve_id": "CVE-2026-93076",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dax/fsdev: clear vmemmap_shift when binding static pgmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93076"
    },
    {
      "rank": 894,
      "cve_id": "CVE-2026-93077",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/features: Clamp Get Feature output size to the remaining buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93077"
    },
    {
      "rank": 895,
      "cve_id": "CVE-2026-93078",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/features: Reject Set Features output buffer smaller than the header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93078"
    },
    {
      "rank": 896,
      "cve_id": "CVE-2026-93079",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/features: Reject Get Feature count larger than the output buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93079"
    },
    {
      "rank": 897,
      "cve_id": "CVE-2026-93080",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Fix transport device teardown lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93080"
    },
    {
      "rank": 898,
      "cve_id": "CVE-2026-93081",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Fix SCMI device destroy lifetimes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93081"
    },
    {
      "rank": 899,
      "cve_id": "CVE-2026-93082",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Unwind P2A receiver mailbox setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93082"
    },
    {
      "rank": 900,
      "cve_id": "CVE-2026-93083",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Unwind TX receiver mailbox setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93083"
    },
    {
      "rank": 901,
      "cve_id": "CVE-2026-93084",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Drop handle on protocol bind failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93084"
    },
    {
      "rank": 902,
      "cve_id": "CVE-2026-93085",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Reject out of range DT protocol IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93085"
    },
    {
      "rank": 903,
      "cve_id": "CVE-2026-93086",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Avoid IDR updates while cleaning channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93086"
    },
    {
      "rank": 904,
      "cve_id": "CVE-2026-93089",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Free transport channel on IDR failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93089"
    },
    {
      "rank": 905,
      "cve_id": "CVE-2026-93090",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Clean up channels on setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93090"
    },
    {
      "rank": 906,
      "cve_id": "CVE-2026-93091",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Quiesce notifications before teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93091"
    },
    {
      "rank": 907,
      "cve_id": "CVE-2026-93092",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Unregister device notifier before IDR teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93092"
    },
    {
      "rank": 908,
      "cve_id": "CVE-2026-93093",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "firmware: arm_scmi: Publish channel state before callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93093"
    },
    {
      "rank": 909,
      "cve_id": "CVE-2026-93094",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath12k: fix dp_link_peer dangling references on AP vdev rollback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93094"
    },
    {
      "rank": 910,
      "cve_id": "CVE-2026-93095",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hfsplus: validate thread record before delete key rebuild",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93095"
    },
    {
      "rank": 911,
      "cve_id": "CVE-2026-93096",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/features: Serialize multi-part Get/Set Feature transfers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93096"
    },
    {
      "rank": 912,
      "cve_id": "CVE-2026-93097",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/mbox: Break poison list loop on an empty payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93097"
    },
    {
      "rank": 913,
      "cve_id": "CVE-2026-93098",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rpmsg: glink: fix deadlock in endpoint destroy during driver detach",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93098"
    },
    {
      "rank": 914,
      "cve_id": "CVE-2026-93099",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/resctrl: Fix UAF from worker threads when domains are removed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93099"
    },
    {
      "rank": 915,
      "cve_id": "CVE-2026-93100",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/resctrl: Prevent use-after-free in rdtgroup_kn_put()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93100"
    },
    {
      "rank": 916,
      "cve_id": "CVE-2026-93101",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: v4l2-async: Unregister sub-device if asc_list is empty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93101"
    },
    {
      "rank": 917,
      "cve_id": "CVE-2026-93102",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/hfi1: Free RX data on late probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93102"
    },
    {
      "rank": 918,
      "cve_id": "CVE-2026-93103",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/hfi1: Preserve unit 0 on allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93103"
    },
    {
      "rank": 919,
      "cve_id": "CVE-2026-93104",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rvt: Return NULL after port allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93104"
    },
    {
      "rank": 920,
      "cve_id": "CVE-2026-93105",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "esp: do not unref managed frag pages in esp_ssg_unref()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93105"
    },
    {
      "rank": 921,
      "cve_id": "CVE-2026-93106",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crash_dump: release keyring reference at the correct time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93106"
    },
    {
      "rank": 922,
      "cve_id": "CVE-2026-93107",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93107"
    },
    {
      "rank": 923,
      "cve_id": "CVE-2026-93108",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/ipoib: Drain RCU callbacks during module teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93108"
    },
    {
      "rank": 924,
      "cve_id": "CVE-2026-93109",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mlx5: Drain RCU callbacks during module teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93109"
    },
    {
      "rank": 925,
      "cve_id": "CVE-2026-93110",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Wait for RCU callbacks before unloading ib_core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93110"
    },
    {
      "rank": 926,
      "cve_id": "CVE-2026-93111",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Mark tracing_multi trampolines as ftrace managed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93111"
    },
    {
      "rank": 927,
      "cve_id": "CVE-2026-93112",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Require a BPF cpumask for bpf_cpumask_populate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93112"
    },
    {
      "rank": 928,
      "cve_id": "CVE-2026-93113",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93113"
    },
    {
      "rank": 929,
      "cve_id": "CVE-2026-93114",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/surface: acpi-notify: Check ACPI companion before use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93114"
    },
    {
      "rank": 930,
      "cve_id": "CVE-2026-93115",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93115"
    },
    {
      "rank": 931,
      "cve_id": "CVE-2026-93116",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: asus-wmi: fix resource leaks on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93116"
    },
    {
      "rank": 932,
      "cve_id": "CVE-2026-93117",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: fix UAF when probe runs concurrent to dyn ID removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93117"
    },
    {
      "rank": 933,
      "cve_id": "CVE-2026-93118",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: aspeed_udc: check endpoint DMA allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93118"
    },
    {
      "rank": 934,
      "cve_id": "CVE-2026-93119",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: ljca: bound bank_num in ljca_enumerate_gpio()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93119"
    },
    {
      "rank": 935,
      "cve_id": "CVE-2026-93120",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: configfs: fix out-of-bounds read of qw_sign",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93120"
    },
    {
      "rank": 936,
      "cve_id": "CVE-2026-93121",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93121"
    },
    {
      "rank": 937,
      "cve_id": "CVE-2026-93122",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: uac: validate rate list length before storing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93122"
    },
    {
      "rank": 938,
      "cve_id": "CVE-2026-93123",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: qcom-geni: do not advance stale DMA completions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93123"
    },
    {
      "rank": 939,
      "cve_id": "CVE-2026-93124",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: asus-wireless: Fail probe when there is no ACPI match",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93124"
    },
    {
      "rank": 940,
      "cve_id": "CVE-2026-93125",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93125"
    },
    {
      "rank": 941,
      "cve_id": "CVE-2026-93126",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "remoteproc: qcom_q6v5_adsp: Fix reference leak for device node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93126"
    },
    {
      "rank": 942,
      "cve_id": "CVE-2026-93127",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Drop scalar id on sign-extending narrowing stack fills",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93127"
    },
    {
      "rank": 943,
      "cve_id": "CVE-2026-93128",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: lg-laptop: Fix LED resource handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93128"
    },
    {
      "rank": 944,
      "cve_id": "CVE-2026-93129",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: dell-wmi-base: Fix handling of ultra performance key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93129"
    },
    {
      "rank": 945,
      "cve_id": "CVE-2026-93130",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: dell-wmi-base: Fix resource leak on module load failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93130"
    },
    {
      "rank": 946,
      "cve_id": "CVE-2026-93131",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: dell-privacy: Fix race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93131"
    },
    {
      "rank": 947,
      "cve_id": "CVE-2026-93132",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93132"
    },
    {
      "rank": 948,
      "cve_id": "CVE-2026-93133",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93133"
    },
    {
      "rank": 949,
      "cve_id": "CVE-2026-93134",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "printk: Fix possible console use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93134"
    },
    {
      "rank": 950,
      "cve_id": "CVE-2026-93135",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject programs with inlined helpers if JIT is not available",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93135"
    },
    {
      "rank": 951,
      "cve_id": "CVE-2026-93136",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93136"
    },
    {
      "rank": 952,
      "cve_id": "CVE-2026-93137",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix use-after-free on mm_struct in bpf_find_vma()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93137"
    },
    {
      "rank": 953,
      "cve_id": "CVE-2026-93138",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93138"
    },
    {
      "rank": 954,
      "cve_id": "CVE-2026-93139",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93139"
    },
    {
      "rank": 955,
      "cve_id": "CVE-2026-93140",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "udf: Mark LVID buffer as uptodate before marking it dirty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93140"
    },
    {
      "rank": 956,
      "cve_id": "CVE-2026-93141",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: r8a66597: avoid double free of ep0_req in probe error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93141"
    },
    {
      "rank": 957,
      "cve_id": "CVE-2026-93142",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thermal/drivers/rcar: Fix error checking in probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93142"
    },
    {
      "rank": 958,
      "cve_id": "CVE-2026-93143",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93143"
    },
    {
      "rank": 959,
      "cve_id": "CVE-2026-93144",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject writes through untrusted BTF pointers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93144"
    },
    {
      "rank": 960,
      "cve_id": "CVE-2026-93145",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93145"
    },
    {
      "rank": 961,
      "cve_id": "CVE-2026-93146",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "time/namespace: Validate nanosecond field in proc_timens_set_offset()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93146"
    },
    {
      "rank": 962,
      "cve_id": "CVE-2026-93147",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/bpf: Replace ly instruction with llgf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93147"
    },
    {
      "rank": 963,
      "cve_id": "CVE-2026-93148",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Reject MEM_ALLOC BTF accesses past object bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93148"
    },
    {
      "rank": 964,
      "cve_id": "CVE-2026-93149",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211_hwsim: avoid NULL skb in stop queue drain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93149"
    },
    {
      "rank": 965,
      "cve_id": "CVE-2026-93150",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cgroup/cpuset: Make nr_deadline_tasks an atomic_t",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93150"
    },
    {
      "rank": 966,
      "cve_id": "CVE-2026-93151",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-rdma: fix response resource leak on queue teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93151"
    },
    {
      "rank": 967,
      "cve_id": "CVE-2026-93152",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-apple: Use acquire/release for queue enabled state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93152"
    },
    {
      "rank": 968,
      "cve_id": "CVE-2026-93153",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/bng_re: return a timeout when firmware responses stall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93153"
    },
    {
      "rank": 969,
      "cve_id": "CVE-2026-93154",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/irdma: Add refcounting to user ring MRs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93154"
    },
    {
      "rank": 970,
      "cve_id": "CVE-2026-93155",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: keembay - Fix AEAD unregister count in error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93155"
    },
    {
      "rank": 971,
      "cve_id": "CVE-2026-93156",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: rk3288 - fail ahash requests on HASH idle timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93156"
    },
    {
      "rank": 972,
      "cve_id": "CVE-2026-93157",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwrng: xilinx-trng - propagate timeout before any data is read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93157"
    },
    {
      "rank": 973,
      "cve_id": "CVE-2026-93158",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: sa2ul - stop probe if context pool creation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93158"
    },
    {
      "rank": 974,
      "cve_id": "CVE-2026-93159",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: atmel-sha204a - fix heap info leak on I2C transfer failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93159"
    },
    {
      "rank": 975,
      "cve_id": "CVE-2026-93160",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: atmel-ecc - reject hardware ECDH without a public key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93160"
    },
    {
      "rank": 976,
      "cve_id": "CVE-2026-93161",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qat - clear AES key schedule from stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93161"
    },
    {
      "rank": 977,
      "cve_id": "CVE-2026-93162",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qat - cancel work on re-enable SR-IOV timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93162"
    },
    {
      "rank": 978,
      "cve_id": "CVE-2026-93163",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwrng: core - fix rng list on registration error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93163"
    },
    {
      "rank": 979,
      "cve_id": "CVE-2026-93164",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "uprobes/x86: Move optimized uprobe from nop5 to nop10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93164"
    },
    {
      "rank": 980,
      "cve_id": "CVE-2026-93165",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/chrome: sensorhub: Fix memory overread in ring handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93165"
    },
    {
      "rank": 981,
      "cve_id": "CVE-2026-93166",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw89: debug: fix off by on in rtw89_ppdu_str()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93166"
    },
    {
      "rank": 982,
      "cve_id": "CVE-2026-93167",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "csky: Fix a4/a5 restoration in syscall trace path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93167"
    },
    {
      "rank": 983,
      "cve_id": "CVE-2026-93168",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93168"
    },
    {
      "rank": 984,
      "cve_id": "CVE-2026-93169",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: zynqmp_dma: fix race between runtime PM and device removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93169"
    },
    {
      "rank": 985,
      "cve_id": "CVE-2026-93170",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93170"
    },
    {
      "rank": 986,
      "cve_id": "CVE-2026-93171",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "leds: lp5860: Fix a potential double-unlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93171"
    },
    {
      "rank": 987,
      "cve_id": "CVE-2026-93172",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93172"
    },
    {
      "rank": 988,
      "cve_id": "CVE-2026-93173",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93173"
    },
    {
      "rank": 989,
      "cve_id": "CVE-2026-93174",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Copy per-CPU map value padding in copy_map_value_long()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93174"
    },
    {
      "rank": 990,
      "cve_id": "CVE-2026-93175",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Fix dangling pointer in CRTC reset function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93175"
    },
    {
      "rank": 991,
      "cve_id": "CVE-2026-93176",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Fix dangling pointer in plane reset function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93176"
    },
    {
      "rank": 992,
      "cve_id": "CVE-2026-93177",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93177"
    },
    {
      "rank": 993,
      "cve_id": "CVE-2026-93178",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93178"
    },
    {
      "rank": 994,
      "cve_id": "CVE-2026-93179",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93179"
    },
    {
      "rank": 995,
      "cve_id": "CVE-2026-93180",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/panthor: Fix NPD issue on partial unmap of an evicted BO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93180"
    },
    {
      "rank": 996,
      "cve_id": "CVE-2026-93181",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/x86/intel/uncore: Fix uncore_box ref/unref ordering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93181"
    },
    {
      "rank": 997,
      "cve_id": "CVE-2026-93182",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched/fair: Fix overflow in update_tg_cfs_runnable()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93182"
    },
    {
      "rank": 998,
      "cve_id": "CVE-2026-93183",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/lima: call drm_mm_init() with a valid allocation range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93183"
    },
    {
      "rank": 999,
      "cve_id": "CVE-2026-93184",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: fsl_audmix: rework runtime PM handling in probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93184"
    },
    {
      "rank": 1000,
      "cve_id": "CVE-2026-93185",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: rt700-sdw: always drain jack work on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93185"
    },
    {
      "rank": 1001,
      "cve_id": "CVE-2026-93186",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/mbox: Clamp mailbox output allocation to the payload size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93186"
    },
    {
      "rank": 1002,
      "cve_id": "CVE-2026-93187",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: SOF: ipc4-topology: Return error for invalid number of formats",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93187"
    },
    {
      "rank": 1003,
      "cve_id": "CVE-2026-93188",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: roccat: bound device-supplied profile index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93188"
    },
    {
      "rank": 1004,
      "cve_id": "CVE-2026-93189",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: core: quiesce input in hid_hw_stop() to prevent use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93189"
    },
    {
      "rank": 1005,
      "cve_id": "CVE-2026-93190",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93190"
    },
    {
      "rank": 1006,
      "cve_id": "CVE-2026-93191",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smack: fix incorrect task context in smack_msg_queue_msgrcv",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93191"
    },
    {
      "rank": 1007,
      "cve_id": "CVE-2026-93192",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/v3d: Clear queue->active_job when v3d_fence_create() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93192"
    },
    {
      "rank": 1008,
      "cve_id": "CVE-2026-93193",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93193"
    },
    {
      "rank": 1009,
      "cve_id": "CVE-2026-93194",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/rockchip: dw_dp: Release core resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93194"
    },
    {
      "rank": 1010,
      "cve_id": "CVE-2026-93195",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93195"
    },
    {
      "rank": 1011,
      "cve_id": "CVE-2026-93196",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvdimm: virtio_pmem: refcount requests for token lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93196"
    },
    {
      "rank": 1012,
      "cve_id": "CVE-2026-93197",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "memcg: move LRU size accounting on reparenting instead of copying it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93197"
    },
    {
      "rank": 1013,
      "cve_id": "CVE-2026-93198",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: validate the persisted dirty_tail chain at load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93198"
    },
    {
      "rank": 1014,
      "cve_id": "CVE-2026-93199",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: Do not treat master device as a duplicate target",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93199"
    },
    {
      "rank": 1015,
      "cve_id": "CVE-2026-93200",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: Fix use-after-free of master->this",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93200"
    },
    {
      "rank": 1016,
      "cve_id": "CVE-2026-93201",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm-pcache: validate seg_id fields from persistent memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93201"
    },
    {
      "rank": 1017,
      "cve_id": "CVE-2026-93202",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: Fix recursive locking during device registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93202"
    },
    {
      "rank": 1018,
      "cve_id": "CVE-2026-93203",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: bla: avoid CRC corruption due to parallel claim add",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93203"
    },
    {
      "rank": 1019,
      "cve_id": "CVE-2026-93204",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: dat: atomically update mac addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93204"
    },
    {
      "rank": 1020,
      "cve_id": "CVE-2026-93372",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-121",
      "title": "Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93372"
    },
    {
      "rank": 1021,
      "cve_id": "CVE-2026-93373",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93373"
    },
    {
      "rank": 1022,
      "cve_id": "CVE-2026-93374",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93374"
    },
    {
      "rank": 1023,
      "cve_id": "CVE-2026-93375",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "title": "Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93375"
    },
    {
      "rank": 1024,
      "cve_id": "CVE-2026-93376",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93376"
    },
    {
      "rank": 1025,
      "cve_id": "CVE-2026-93377",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93377"
    },
    {
      "rank": 1026,
      "cve_id": "CVE-2026-93378",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93378"
    },
    {
      "rank": 1027,
      "cve_id": "CVE-2026-93379",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93379"
    },
    {
      "rank": 1028,
      "cve_id": "CVE-2026-93380",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "title": "Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93380"
    },
    {
      "rank": 1029,
      "cve_id": "CVE-2026-93381",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93381"
    },
    {
      "rank": 1030,
      "cve_id": "CVE-2026-93382",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93382"
    },
    {
      "rank": 1031,
      "cve_id": "CVE-2026-93383",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93383"
    },
    {
      "rank": 1032,
      "cve_id": "CVE-2026-93384",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-918",
      "title": "Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93384"
    },
    {
      "rank": 1033,
      "cve_id": "CVE-2026-93385",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93385"
    },
    {
      "rank": 1034,
      "cve_id": "CVE-2026-93386",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93386"
    },
    {
      "rank": 1035,
      "cve_id": "CVE-2026-93387",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-754",
      "title": "Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93387"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-87886",
      "detail": "ADDED TO KEV — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Remediation due September 19, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-11222",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-11222 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-21626",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-56005",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-56005. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-68624",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-68624 (N-able Mail Assure). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71338",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71338 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42578 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42579 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42584 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47094",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47094 (SIMAC MyPHR). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57147",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57147 (MervinPraison PraisonAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59255 (SpecterOps BloodHound). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59258",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59258 (immich-app immich). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62239",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62239 (Dao-AILab flash-attention). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63765 (chatwoot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63768",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63768 (calcom cal.diy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66005",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66005 (janhq jan). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67278 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69114",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69114 (Spacebar Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69116",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69116 (xpf0000 FlyEnv). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73033 (sucuri-wordpress-plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74926",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74926 (Unknown MultiVendorX). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76550",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76550 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76551",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76551 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76552",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76552 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76553",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76553 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76555",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76555 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76556",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76556 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76557",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76557 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76558",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76558 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-76559",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-76559 (Unknown WP Import Export Lite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77702",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77702 (Unknown Eventin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78472",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78472 (Unknown Ni WooCommerce Sales Report). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78474",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78474 (Unknown Ni WooCommerce Sales Report). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79418",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79418. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79419",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79419. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82124",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82124 (Unknown Schema & Structured Data for WP & AMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82125",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82125 (Unknown Schema & Structured Data for WP & AMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82126",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82126 (Unknown Schema & Structured Data for WP & AMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82964",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82964 (Gen Digital Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84088",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84088 (Unknown Xpro Addons — 140+ Widgets for Elementor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84829",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84829 (Unknown Optimole). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84905",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84905 (Unknown Eventin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84907",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84907 (Unknown Eventin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85131",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85131 (Unknown WPLP Cookie Consent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85349",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85349 (Unknown FluentBoards). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85530",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85530 (Unknown GiveWP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85569",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85569 (Unknown Tutor LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85572",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85572 (Unknown Tutor LMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85641",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85641 (Unknown Formidable Forms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86444",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86444 (Unknown LearnPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86445",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86445 (Unknown LearnPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86447",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86447 (Unknown LearnPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86448",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86448 (Unknown LearnPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86449",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86449 (Unknown LearnPress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86784",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86784 (Unknown Visualizer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86823",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86823 (Unknown Newsletter). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87828 (Unknown Seraphinite Accelerator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87854",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87854 (Unknown Subscriptions for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87860",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87860 (Unknown Subscriptions for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87896",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87896 (Unknown Rox Appointment Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87907",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87907 (Unknown Rox Appointment Booking). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87959",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87959 (Unknown WPBot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-88910",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-88910 (Unknown kboard). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89327",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89327 (Unknown FluentBoards). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89328",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89328 (Unknown FluentBoards). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90881 (D-Link DIR-882). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91005",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91005 (SourceCodester Online Faculty Clearance System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91090",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91090 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91849 (WuzhiCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91993",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91993 (dromara Jpom). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91996",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91996 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91998 (casdoor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92455",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92455 (guchengwuyue yshop-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92460",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92460 (guchengwuyue yshop-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92474",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92474 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92527",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92527 (chatwoot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92774 (requarks Wiki.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92806",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92806 (phpList). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92809",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92809 (PrestaShop psgdpr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92810",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92810 (PrestaShop blockwishlist). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92813",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92813 (Metabase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92814",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92814 (dgtlmoon changedetection.io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92815",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92815 (dgtlmoon changedetection.io). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-48710",
      "detail": "DUE DATE PASSED — CVE-2026-48710 (Kludex starlette). CISA remediation deadline was September 16, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-59822",
      "detail": "DUE DATE PASSED — CVE-2026-59822 (BerriAI litellm). CISA remediation deadline was September 16, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-4622",
      "detail": "RESCORED — CVE-2023-4622 (Linux Kernel). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-43697",
      "detail": "RESCORED — CVE-2026-43697 (Apple macOS). CVSS 4.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58704",
      "detail": "RESCORED — CVE-2026-58704 (Google Android). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-67378",
      "detail": "RESCORED — CVE-2026-67378 (Microsoft SQL Server 2019 (CU 32)). CVSS 8.5 → 9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-67631",
      "detail": "RESCORED — CVE-2026-67631 (Microsoft SQL Server 2017 (CU 31)). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-67636",
      "detail": "RESCORED — CVE-2026-67636 (Microsoft SQL Server 2019 (CU 32)). CVSS 8.5 → 9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-67643",
      "detail": "RESCORED — CVE-2026-67643 (Microsoft SQL Server 2022 (CU 26)). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72980",
      "detail": "RESCORED — CVE-2026-72980 (Microsoft Windows 10 Version 1607). CVSS 4.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-79419",
      "detail": "RESCORED — CVE-2026-79419. CVSS 6.1 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82874",
      "detail": "RESCORED — CVE-2026-82874 (ToolJet). CVSS 2.4 → 9.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-86865",
      "detail": "RESCORED — CVE-2026-86865 (Tanium Asset). CVSS 8.8 → 7.2 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-56395",
      "detail": "REJECTED — CVE-2026-56395 (SiYuan). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15565",
      "detail": "PATCH SHIPPED — CVE-2026-15565 (Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7). Fixed in Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-15567",
      "detail": "PATCH SHIPPED — CVE-2026-15567 (Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7). Fixed in Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
