{
  "day": "2026-09-18",
  "boundary": "UTC calendar day",
  "published_count": 514,
  "by_severity": {
    "CRITICAL": 51,
    "HIGH": 207,
    "MEDIUM": 207,
    "LOW": 42
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 7,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-18912",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.015,
      "epss_percentile": 0.73103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine DataSecurity Plus",
      "cwe": "CWE-89",
      "title": "ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18912"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-93371",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01351,
      "epss_percentile": 0.70253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marcopiovanello",
      "product": "yt-dlp-web-ui",
      "cwe": "CWE-74",
      "title": "marcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93371"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-18911",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01062,
      "epss_percentile": 0.63079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine DataSecurity Plus",
      "cwe": "CWE-20",
      "title": "ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18911"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-14323",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00939,
      "epss_percentile": 0.59343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "printcart",
      "product": "Printcart Store – Web to Print Product Designer for WooCommerce",
      "cwe": "CWE-22",
      "title": "Printcart Web to Print Product Designer for WooCommerce <= 2.8.5 - Unauthenticated Arbitrary File Read via 'folder' and 'mockups' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14323"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-17086",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0089,
      "epss_percentile": 0.57774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shortpixel",
      "product": "ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF",
      "cwe": "CWE-502",
      "title": "ShortPixel Image Optimizer <= 6.5.5 - Authenticated (Author+) PHP Object Injection via Nested JSON Post Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17086"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-16777",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00657,
      "epss_percentile": 0.49954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jkohlbach",
      "product": "Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers",
      "cwe": "CWE-22",
      "title": "Store Exporter <= 2.8.0 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16777"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-15579",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00652,
      "epss_percentile": 0.49751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "TN-4500B Series",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This may allow a remote attacker to submit a specially crafted overly long input, triggering a buffer overflow that can cause the authentication process to crash and result in a Denial of Service (DoS) attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15579"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-89059",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00556,
      "epss_percentile": 0.45139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "RESTEasy",
      "cwe": "CWE-409",
      "title": "Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89059"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-93467",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.43055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HGiga",
      "product": "OAKlouds-custom_page-2.0",
      "cwe": "CWE-502",
      "title": "HGiga｜OAKlouds - Insecure Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93467"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-13639",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00505,
      "epss_percentile": 0.42152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-331",
      "title": "An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13639"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-18442",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00497,
      "epss_percentile": 0.41644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wclovers",
      "product": "WCFM Marketplace – Multivendor Marketplace for WooCommerce",
      "cwe": "CWE-89",
      "title": "WCFM Marketplace <= 3.8.2 - Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18442"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-18405",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.40924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegtheme",
      "product": "Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress",
      "cwe": "CWE-79",
      "title": "Jeg Kit for Elementor <= 3.2.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18405"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-87915",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.40072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danieliser",
      "product": "Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder",
      "cwe": "CWE-79",
      "title": "Popup Maker <= 1.24.0 - Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87915"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-93468",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.39178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HGiga",
      "product": "OAKlouds-bulletin_v3-2.0",
      "cwe": "CWE-23",
      "title": "HGiga｜OAKlouds - Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93468"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-12954",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mapster",
      "product": "Mapster WP Maps",
      "cwe": "CWE-20",
      "title": "Mapster WP Maps <= 1.23.0 - Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12954"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-13684",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00455,
      "epss_percentile": 0.38816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-116",
      "title": "An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13684"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-40535",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00434,
      "epss_percentile": 0.37155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-22",
      "title": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40535"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-15797",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0043,
      "epss_percentile": 0.36827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danieliser",
      "product": "Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder",
      "cwe": "CWE-79",
      "title": "Popup Maker <= 1.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15797"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-87743",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00429,
      "epss_percentile": 0.3675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Exploit Intelligence",
      "cwe": "CWE-551",
      "title": "Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus http security",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87743"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-85652",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.3498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Photo Gallery by 10Web – Mobile-Friendly Image Gallery",
      "cwe": "CWE-89",
      "title": "Photo Gallery by 10Web <= 1.8.44 - Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85652"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-93310",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.34549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "O-RAN-SC",
      "product": "SMO OAM",
      "cwe": "CWE-400",
      "title": "O-RAN-SC SMO OAM VES Collector allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93310"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-75961",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00377,
      "epss_percentile": 0.31528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webaways",
      "product": "NEX-Forms – Ultimate Forms Plugin for WordPress",
      "cwe": "CWE-89",
      "title": "NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75961"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-92976",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.31368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "T-Systems",
      "product": "TAO",
      "cwe": "CWE-613",
      "title": "Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92976"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-15275",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.31275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpexpertsio",
      "product": "WP Multi Store Locator Pro",
      "cwe": "CWE-89",
      "title": "WP Multi Store Locator Pro <= 4.5.1 - Unauthenticated SQL Injection via 'store_locator_search_radius' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15275"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-92619",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevelop",
      "product": "Booking Calendar",
      "cwe": "CWE-269",
      "title": "Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92619"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-40536",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.3078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-22",
      "title": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40536"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-67100",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00353,
      "epss_percentile": 0.28953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-89",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67100"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-40530",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.28372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-93",
      "title": "An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40530"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-17607",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.2795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chuck1982",
      "product": "WP Inventory Manager",
      "cwe": "CWE-89",
      "title": "WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17607"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-4036",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.27302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-89",
      "title": "An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4036"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-85705",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.27161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AyeCode Ltd",
      "product": "Location Manager",
      "cwe": "CWE-89",
      "title": "Location Manager <= 2.3.38 - Unauthenticated SQL Injection via 'latitude' and 'longitude' REST API Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85705"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-12739",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.27213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "WP Easy Pay – Payment and Donation Form Builder for Square",
      "cwe": "CWE-862",
      "title": "WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12739"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-93312",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.27245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Freedesktop",
      "product": "Poppler",
      "cwe": "CWE-404",
      "title": "Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93312"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-40531",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-190",
      "title": "An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40531"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-89058",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "RESTEasy",
      "cwe": null,
      "title": "Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89058"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-13471",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
      "cwe": "CWE-639",
      "title": "LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13471"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-79954",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "CryptoLib",
      "cwe": "CWE-306",
      "title": "NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79954"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-40532",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.25268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-425",
      "title": "A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40532"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-93311",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00319,
      "epss_percentile": 0.25103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Freedesktop",
      "product": "Poppler",
      "cwe": "CWE-189",
      "title": "Freedesktop Poppler SampledFunction Function.cc integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93311"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-6205",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-73",
      "title": "An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6205"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-75017",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpblockart",
      "product": "Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid",
      "cwe": "CWE-862",
      "title": "Magazine Blocks <= 1.8.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification / Site-Wide Template Takeover via Builder Templates REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75017"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-93331",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93331"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-85410",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixarlabs",
      "product": "Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits",
      "cwe": "CWE-862",
      "title": "Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85410"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-12384",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TECHIN2B",
      "product": "TECHIN2B Application",
      "cwe": "CWE-639",
      "title": "Broken Access Control in TECHIN2B Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12384"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-17586",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kurudrive",
      "product": "VK All in One Expansion Unit",
      "cwe": "CWE-79",
      "title": "VK All in One Expansion Unit <= 9.118.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17586"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-13673",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.2351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-732",
      "title": "An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13673"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-40533",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-202",
      "title": "An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40533"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-83561",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.22066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "complianz",
      "product": "Complianz GDPR/CCPA Cookie Consent Banner",
      "cwe": "CWE-79",
      "title": "Complianz GDPR/CCPA Cookie Consent Banner <= 7.5.4 - Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83561"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-89413",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "farazfrank",
      "product": "Filter Gallery",
      "cwe": "CWE-862",
      "title": "Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89413"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-92991",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator",
      "cwe": "CWE-79",
      "title": "Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92991"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-88994",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All Bootstrap Blocks",
      "cwe": "CWE-98",
      "title": "All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88994"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-17576",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.20125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "revmakx",
      "product": "InfiniteWP Client",
      "cwe": "CWE-89",
      "title": "InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17576"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-90981",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.20002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "satollo",
      "product": "Newsletter – Send awesome emails from WordPress",
      "cwe": "CWE-79",
      "title": "Newsletter <= 9.3.8 - Reflected Cross-Site Scripting via 'nn' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90981"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-67102",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-285",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67102"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-90977",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Clean Login",
      "cwe": "CWE-697",
      "title": "Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90977"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-67101",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-918",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67101"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-13635",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-116",
      "title": "An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13635"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-92249",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qodeinteractive",
      "product": "Qi Addons For Elementor",
      "cwe": "CWE-79",
      "title": "Qi Addons For Elementor <= 1.11 - Reflected DOM-Based Cross-Site Scripting via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92249"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-92554",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin",
      "cwe": "CWE-79",
      "title": "ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Parameter Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92554"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-91707",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.1863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elegant Themes",
      "product": "Divi",
      "cwe": "CWE-862",
      "title": "Divi <= 5.11.1 - Missing Authorization to Unauthenticated Arbitrary Registered Shortcode Execution via 'content' Parameter via Shortcode Module REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91707"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-14472",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "extendthemes",
      "product": "Kubio AI Page Builder",
      "cwe": "CWE-79",
      "title": "Kubio AI Page Builder <= 2.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14472"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-93455",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.1778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "batiste",
      "product": "django-page-cms",
      "cwe": "CWE-862",
      "title": "django-page-cms through 2.0.13 Unauthorized Content Access via Staff Account",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93455"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-89278",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "john-dagelmore",
      "product": "GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI",
      "cwe": "CWE-200",
      "title": "GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89278"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-56592",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-307",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56592"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-40537",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-918",
      "title": "A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40537"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-86796",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hide My WP Ghost",
      "cwe": "CWE-693",
      "title": "WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86796"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-86800",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hide My WP Ghost",
      "cwe": "CWE-693",
      "title": "WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86800"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-13683",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-89",
      "title": "An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13683"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-40538",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.16637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-307",
      "title": "An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40538"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-12106",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "airani",
      "product": "Auto Upload Images",
      "cwe": "CWE-918",
      "title": "Auto Upload Images <= 3.3.2 - Authenticated (Contributor+) Server-Side Request Forgery via 'src' Attribute of <img> Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12106"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-93313",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.16393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Freedesktop",
      "product": "Poppler",
      "cwe": "CWE-189",
      "title": "Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93313"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-93314",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.16392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Freedesktop",
      "product": "Poppler",
      "cwe": "CWE-189",
      "title": "Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93314"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2024-38639",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-287",
      "title": "QTS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-38639"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-92622",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpchill",
      "product": "Strong Testimonials",
      "cwe": "CWE-79",
      "title": "Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92622"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-15004",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninjateam",
      "product": "FileBird – WordPress Media Library Folders & File Manager",
      "cwe": "CWE-79",
      "title": "FileBird – WordPress Media Library Folders & File Manager <= 6.5.6 - Authenticated (Author+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15004"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-77169",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Team Folders",
      "cwe": "CWE-284",
      "title": "A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77169"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-92714",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Download Manager",
      "cwe": "CWE-639",
      "title": "Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92714"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-84909",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Custom Twitter Feeds – A Tweets Widget or X Feed Widget",
      "cwe": "CWE-79",
      "title": "Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84909"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-92561",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevelop",
      "product": "Booking Calendar",
      "cwe": "CWE-79",
      "title": "Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92561"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-89138",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "farazfrank",
      "product": "Filter Gallery",
      "cwe": "CWE-862",
      "title": "Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'image_id' Parameter via ufg_save_gallery AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89138"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-84738",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00224,
      "epss_percentile": 0.13302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AF Companion",
      "cwe": "CWE-94",
      "title": "AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84738"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-67103",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-79",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67103"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-90884",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brechtvds",
      "product": "WP Recipe Maker",
      "cwe": "CWE-79",
      "title": "WP Recipe Maker <= 10.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90884"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-90976",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Clean Login",
      "cwe": "CWE-284",
      "title": "Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90976"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-79713",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Breeze Cache",
      "cwe": "CWE-444",
      "title": "Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79713"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-18317",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "foxtheme",
      "product": "Foxtool All-in-One: Contact chat button, Custom login, Media optimize images",
      "cwe": "CWE-862",
      "title": "Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via 'option_key' Parameter of toggle_watermark AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18317"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-15650",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themewant",
      "product": "RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg",
      "cwe": "CWE-79",
      "title": "RT Mega Menu <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15650"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-89330",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents",
      "cwe": "CWE-79",
      "title": "EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89330"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-21822",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL AppScan 360°",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21822"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-82980",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Files Lock",
      "cwe": "CWE-287",
      "title": "Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authenticated session user. This enables: Cross-user manual locks : attacker locks a victim's files, blocking writes (PUT/MOVE/DELETE, editor saves). Lock-token disclosure: the app returns the lock token to unauthorized callers, enabling them to remove token-based locks (client locks) of other users.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82980"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-93494",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93494"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-40534",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-79",
      "title": "An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40534"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-82985",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Server",
      "cwe": "CWE-284",
      "title": "The Photos app's filter-based \"smart albums\" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine which of the owner's files are searched — allowing them to discover files (name, file ID, and other metadata) in folders the album owner never intended to include in the shared album. This requires the album owner to have shared a filter-based smart album with the attacker; it does not allow access to arbitrary users' files without such a share.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82985"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-14855",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themewant",
      "product": "RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg",
      "cwe": "CWE-79",
      "title": "RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14855"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-75016",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpblockart",
      "product": "Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid",
      "cwe": "CWE-79",
      "title": "Magazine Blocks <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'clientId' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75016"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-21848",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-284",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21848"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2025-13533",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.0955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wipeoutmedia",
      "product": "CSS & JavaScript Toolbox",
      "cwe": "CWE-79",
      "title": "CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Assignment Engine Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13533"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-13623",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-79",
      "title": "An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13623"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-13666",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00193,
      "epss_percentile": 0.09333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-93",
      "title": "An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13666"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-87767",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wp shortcut link and advertisement baner",
      "cwe": "CWE-89",
      "title": "WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87767"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-87770",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Price Drop Alert for Woo Commerce",
      "cwe": "CWE-89",
      "title": "Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87770"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-87771",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Question and Answer",
      "cwe": "CWE-89",
      "title": "Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87771"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-87774",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tz Weekly Radio Schedule",
      "cwe": "CWE-89",
      "title": "Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87774"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-87775",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tz Weekly Radio Schedule",
      "cwe": "CWE-89",
      "title": "Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87775"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-82982",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Approval",
      "cwe": "CWE-840",
      "title": "The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82982"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-85122",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Form Builder by WhiteStudio",
      "cwe": "CWE-79",
      "title": "Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85122"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-11757",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KA Informatics Technologies Ltd. Co.",
      "product": "Bar Association Website",
      "cwe": "CWE-79",
      "title": "Reflected XSS in KA Informatics' Bar Association Website",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11757"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-88825",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.0697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "iGMS Direct Booking",
      "cwe": "CWE-79",
      "title": "iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88825"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-75157",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.06985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-863",
      "title": "Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75157"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-85127",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85127"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-56590",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-434",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56590"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-84902",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "King Addons for Elementor",
      "cwe": "CWE-79",
      "title": "King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Catalog Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84902"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-93485",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Automattic",
      "product": "WordPress",
      "cwe": "CWE-79",
      "title": "WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93485"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-56597",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-200",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56597"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-77170",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Deck",
      "cwe": "CWE-284",
      "title": "The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77170"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-88993",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All Bootstrap Blocks",
      "cwe": "CWE-79",
      "title": "All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88993"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-93456",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "batiste",
      "product": "django-page-cms",
      "cwe": "CWE-352",
      "title": "django-page-cms through 2.0.13 CSRF via admin mutation views",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93456"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-93493",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-299",
      "title": "Io.netty/netty-handler-ssl-ocsp: netty: ocsp validation silently skipped when a response omits the optional nextupdate field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93493"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-84903",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00149,
      "epss_percentile": 0.04526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "King Addons for Elementor",
      "cwe": "CWE-200",
      "title": "King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84903"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-56595",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix Service Management",
      "cwe": "CWE-942",
      "title": "HCL BigFix Service Management is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56595"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-85009",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.0427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RestroPress",
      "cwe": "CWE-639",
      "title": "RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment Recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85009"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-85123",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.0427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Form Builder by WhiteStudio",
      "cwe": "CWE-284",
      "title": "Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85123"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-85350",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.0427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "UpsellWP",
      "cwe": "CWE-287",
      "title": "UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85350"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-87966",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-639",
      "title": "Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87966"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-87965",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.0427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-284",
      "title": "Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87965"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-88798",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Really Simple Security",
      "cwe": "CWE-400",
      "title": "Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88798"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-81810",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.0385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All-in-One WP Migration and Backup",
      "cwe": "CWE-269",
      "title": "All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin via Import Secret Key Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81810"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-81340",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81340"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-84904",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.03851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "King Addons for Elementor",
      "cwe": "CWE-862",
      "title": "King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84904"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-68493",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Server",
      "cwe": "CWE-639",
      "title": "After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68493"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-89008",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00139,
      "epss_percentile": 0.03671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bookit — Booking & Appointment Calendar",
      "cwe": "CWE-200",
      "title": "Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89008"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-90984",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.0343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Generate PDF using Contact Form 7",
      "cwe": "CWE-918",
      "title": "Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Request Forgery via Array-Valued Form Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90984"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-90978",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Filter Gallery",
      "cwe": "CWE-284",
      "title": "Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90978"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-88844",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88844"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-89007",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bookit — Booking & Appointment Calendar",
      "cwe": "CWE-862",
      "title": "Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89007"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2024-27123",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QcalAgent",
      "cwe": "CWE-79",
      "title": "QcalAgent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-27123"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-77164",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Server",
      "cwe": "CWE-918",
      "title": "Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ reach this code path, allowing any unauthenticated user to force the server to issue a GET request to an internal address. The response body of the internal request is never returned to the requester, so this is blind SSRF: an attacker can determine whether an internal service is reachable, but cannot read its response contents through this endpoint alone.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77164"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-40539",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00076,
      "epss_percentile": 0.00114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-295",
      "title": "An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40539"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2025-15399",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-352",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15399"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-10747",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ Appliance",
      "cwe": "CWE-122",
      "title": "IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10747"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-93603",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-94",
      "title": "vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93603"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-93605",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 NodeVM before 3.12.1 Remote Code Execution via child_process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93605"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-93606",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93606"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2025-53837",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xwiki",
      "product": "xwiki-rendering",
      "cwe": "CWE-95",
      "title": "org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53837"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-10858",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ for HPE NonStop",
      "cwe": "CWE-122",
      "title": "IBM MQ for HPE NonStop is vulnerable to a denial of service attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10858"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-61682",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kcp-dev",
      "product": "kcp",
      "cwe": "CWE-290",
      "title": "kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61682"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-61781",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpartman",
      "product": "pg_partman",
      "cwe": "CWE-89",
      "title": "pg_partman has privilege escalation through SQL injection in create_partition_time()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61781"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-77240",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArnasDon",
      "product": "wacrm",
      "cwe": "CWE-639",
      "title": "WACRM: Database-layer authorization bypasses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77240"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-80442",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80442"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-84064",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84064"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-84075",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-306",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84075"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-84078",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-306",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84078"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2025-66455",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-502",
      "title": "LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66455"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-58264",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluidSynth",
      "product": "fluidsynth",
      "cwe": "CWE-122",
      "title": "FluidSynth: Heap-based buffer overrun",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58264"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-61550",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Icinga",
      "product": "icinga2",
      "cwe": "CWE-862",
      "title": "Icinga 2: Improper access control for JSON-RPC update certificate messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61550"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-75031",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interchange",
      "product": "Interchange",
      "cwe": "CWE-94",
      "title": "In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75031"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-80441",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80441"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-81657",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-502",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81657"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-82340",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-94",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82340"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-82967",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-306",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82967"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-84082",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84082"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-84383",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-787",
      "title": "libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84383"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-82832",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-79",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82832"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-28197",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cohesity",
      "product": "NetBackup Flex OS",
      "cwe": "CWE-88",
      "title": "Privilege Escalation via Argument Injection in NetBackup Flex OS Shell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28197"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-28198",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cohesity",
      "product": "NetBackup Flex OS",
      "cwe": "CWE-347",
      "title": "Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28198"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2023-54399",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hongjing",
      "product": "e-HR",
      "cwe": "CWE-89",
      "title": "Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54399"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-63647",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-306",
      "title": "CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63647"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-75885",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-918",
      "title": "Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75885"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-81321",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "HMT.CM2507 Firmware",
      "cwe": "CWE-312",
      "title": "CareCam CM2507 Cleartext Storage of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81321"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-85497",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "HMT.CM2507 Firmware",
      "cwe": "CWE-916",
      "title": "CareCam CM2507 Use of Password Hash With Insufficient Computational Effort",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85497"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-93659",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "concretecms-community-store",
      "product": "community_store",
      "cwe": "CWE-79",
      "title": "Concrete CMS Community Store before 2.7.8 Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93659"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-93740",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-119",
      "title": "Totolink A3002MU formWlEncrypt buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93740"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-93839",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-306",
      "title": "LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93839"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2023-5778",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "Freelance Controller DCP",
      "cwe": "CWE-130",
      "title": "Missing Length Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-5778"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-93762",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-470",
      "title": "Data deletion and attribute disclosure via field-name method injection in in-memory queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93762"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-93868",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-338",
      "title": "Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93868"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-59163",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AxDSan",
      "product": "mnemosyne",
      "cwe": "CWE-347",
      "title": "Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59163"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-75878",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling File Gateway",
      "cwe": "CWE-287",
      "title": "IBM Sterling File Gateway is Vulnerable to Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75878"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-84073",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84073"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-92701",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultravioletrs",
      "product": "cocos",
      "cwe": "CWE-346",
      "title": "Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92701"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-92702",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultravioletrs",
      "product": "cocos",
      "cwe": "CWE-346",
      "title": "Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92702"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-93019",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Imager",
      "cwe": "CWE-196",
      "title": "Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93019"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-84031",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-79",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84031"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-84070",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-79",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84070"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-84074",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-79",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84074"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-84106",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-79",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84106"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2025-14754",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "IBM Cloud Pak for Data is vulnerable to OS command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14754"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-10575",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-122",
      "title": "IBM MQ queue manager is vulnerable to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10575"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-11375",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-122",
      "title": "IBM MQ queue manager is vulnerable to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11375"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-11378",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-190",
      "title": "IBM MQ queue manager is vulnerable to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11378"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-11381",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ for HPE NonStop",
      "cwe": "CWE-122",
      "title": "IBM MQ for HPE NonStop is vulnerable to a denial of service issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11381"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-11725",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-190",
      "title": "IBM MQ queue manager is vulnerable to privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11725"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-33625",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-400",
      "title": "LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33625"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-58197",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stacklok",
      "product": "toolhive",
      "cwe": "CWE-284",
      "title": "ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58197"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-81180",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syslifters",
      "product": "sysreptor",
      "cwe": "CWE-20",
      "title": "SysReptor: Authenticated RCE by insecure image processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81180"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-81656",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81656"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-81933",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81933"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-82885",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-862",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82885"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-82887",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82887"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-84034",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-798",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84034"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-84084",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-352",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84084"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-88622",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88622"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-93031",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Cloud Plugins/_deleeuw_",
      "product": "Use-your-Drive | Google Drive plugin for WordPress",
      "cwe": "CWE-434",
      "title": "WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box <= 3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload via Media Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93031"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-93759",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-94",
      "title": "Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93759"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2017-20284",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Caucho Technology, Inc.",
      "product": "Resin",
      "cwe": "CWE-22",
      "title": "Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20284"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2019-25776",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weaver Network Co., Ltd.",
      "product": "E-cology",
      "cwe": "CWE-89",
      "title": "Weaver E-cology SQL Injection via SyncUserInfo.jsp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25776"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2021-48008",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chanjet Information Technology Co., Ltd.",
      "product": "CRM",
      "cwe": "CWE-89",
      "title": "Chanjet CRM SQL Injection via get_usedspace.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-48008"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-62943",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digint",
      "product": "btrbk",
      "cwe": "CWE-78",
      "title": "btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62943"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-68914",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mojolicious",
      "product": "mojo",
      "cwe": "CWE-400",
      "title": "Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68914"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-77929",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-434",
      "title": "ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77929"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-81942",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET IGS-5225-8P2T4S V1",
      "cwe": "CWE-78",
      "title": "PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81942"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-84398",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "HMT.CM2507 Firmware",
      "cwe": "CWE-258",
      "title": "CareCam CM2507 Empty Password in Configuration File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84398"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-86520",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bransys",
      "product": "ELD",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in Bransys ELD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86520"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-88259",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "HMT.CM2507 Firmware",
      "cwe": "CWE-306",
      "title": "CareCam CM2507 Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88259"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-93592",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-129",
      "title": "vLLM before 0.28.0 Denial of Service via negative token ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93592"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-93599",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustls",
      "product": "webpki",
      "cwe": "CWE-191",
      "title": "rustls-webpki before 0.103.13 Panic via empty BIT STRING",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93599"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-93657",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hickory-dns",
      "product": "hickory-resolver",
      "cwe": "CWE-347",
      "title": "hickory-resolver before 0.26.2 DNSSEC Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93657"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-93687",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "micromatch",
      "product": "braces",
      "cwe": "CWE-674",
      "title": "braces through 3.0.3 Stack Overflow via Deeply Nested Patterns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93687"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-93688",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgl-project",
      "product": "sglang",
      "cwe": "CWE-770",
      "title": "SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93688"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-93690",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "garycourt",
      "product": "uri-js",
      "cwe": "CWE-835",
      "title": "uri-js through 4.4.1 Denial of Service via removeDotSegments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93690"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-93748",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kornelski",
      "product": "http-cache-semantics",
      "cwe": "CWE-524",
      "title": "http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93748"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-93749",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "7rulnik",
      "product": "source-map-js",
      "cwe": "CWE-1284",
      "title": "source-map-js through 1.2.1 Event Loop Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93749"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-93752",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NV",
      "product": "CSSOM",
      "cwe": "CWE-915",
      "title": "CSSOM through 0.5.0 Denial of Service via length Property",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93752"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-93753",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TehShrike",
      "product": "deepmerge",
      "cwe": "CWE-1321",
      "title": "deepmerge through 4.3.1 Prototype Poisoning via mergeObject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93753"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-93761",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-1333",
      "title": "Denial of service via unbounded regex matching in Mongoid's in-memory query matcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93761"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2025-61682",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SemanticMediaWiki",
      "product": "SemanticMediaWiki",
      "cwe": "CWE-79",
      "title": "Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61682"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-17619",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "spectrum-lsf : IBM Platform RTM",
      "cwe": "CWE-89",
      "title": "The IBM Platform RTM is affected by an SQL injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17619"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-61551",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Icinga",
      "product": "icinga2",
      "cwe": "CWE-674",
      "title": "Icinga 2: Stack overflow via deeply nested JSON objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61551"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-68928",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acode-Foundation",
      "product": "Acode",
      "cwe": "CWE-749",
      "title": "Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68928"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-81626",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81626"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-93593",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-863",
      "title": "ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93593"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-93738",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-119",
      "title": "Totolink A3002MU formSchedule buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93738"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-93739",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-119",
      "title": "Totolink A3002MU formWlAc buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93739"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-93758",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-639",
      "title": "Cross-principal document update, theft, and deletion via unvalidated id in nested attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93758"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-93922",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan through 3.8.4 Stored XSS via notebook names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93922"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-93923",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan through 3.8.4 Stored XSS via Heading Style Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93923"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-61817",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpartman",
      "product": "pg_partman",
      "cwe": "CWE-89",
      "title": "pg_partman privilege escalation via SQL injection in several functions via time decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61817"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-61818",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpartman",
      "product": "pg_partman",
      "cwe": "CWE-89",
      "title": "pg_partman SQL injection in undo partition time encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61818"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-61819",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpartman",
      "product": "pg_partman",
      "cwe": "CWE-89",
      "title": "pg_partman privilege escalation via SQL injection in when using pg_jobmon and encountering exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61819"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-61820",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpartman",
      "product": "pg_partman",
      "cwe": "CWE-89",
      "title": "pg_partman privilege escalation via SQL injection when inheriting template properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61820"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-61821",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpartman",
      "product": "pg_partman",
      "cwe": "CWE-862",
      "title": "pg_partman authorization bypass to move child tables between schemas during retention",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61821"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-81943",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET IGS-5225-8P2T4S V1",
      "cwe": "CWE-489",
      "title": "PLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81943"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-63199",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perses",
      "product": "perses",
      "cwe": "CWE-862",
      "title": "Perses: Missing authorization in datasource proxy allows cross-scope secret disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63199"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-63638",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-787",
      "title": "OpenImageIO: Cineon invalid bit depth heap out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63638"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-93760",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-943",
      "title": "NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93760"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-93765",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-470",
      "title": "Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93765"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-55556",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rsyslog",
      "product": "rsyslog",
      "cwe": "CWE-122",
      "title": "Rsyslog: Heap buffer overflow in imhttp plugin Basic Authentication handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55556"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-57228",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-125",
      "title": "Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57228"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-86689",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bransys",
      "product": "ELD",
      "cwe": "CWE-319",
      "title": "Cleartext Transmission of Sensitive Information in Bransys ELD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86689"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-91127",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flyfish-dev",
      "product": "file-viewer",
      "cwe": "CWE-79",
      "title": "File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91127"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-93569",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-444",
      "title": "Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93569"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-93750",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kornelski",
      "product": "http-cache-semantics",
      "cwe": "CWE-436",
      "title": "http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93750"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-93838",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgl-project",
      "product": "sglang",
      "cwe": "CWE-770",
      "title": "SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93838"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-10027",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-787",
      "title": "IBM MQ queue manager is vulnerable to unauthenticated remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10027"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-11726",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ for HPE NonStop",
      "cwe": "CWE-125",
      "title": "IBM MQ for HPE NonStop is vulnerable to a denial of service issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11726"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-11727",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ for HPE NonStop",
      "cwe": "CWE-122",
      "title": "IBM MQ for HPE NonStop is vulnerable to a denial of service issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11727"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-54148",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4k",
      "product": "http4k",
      "cwe": "CWE-294",
      "title": "http4k: `DigestAuthProvider.verify` did not bind to request URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54148"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-61548",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rsyslog",
      "product": "rsyslog",
      "cwe": "CWE-121",
      "title": "Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61548"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-61833",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "project-zot",
      "product": "zot",
      "cwe": "CWE-285",
      "title": "zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61833"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-62278",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hargata",
      "product": "lubelog",
      "cwe": "CWE-22",
      "title": "LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticated Users to Write Files Outside Data Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62278"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-77239",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArnasDon",
      "product": "wacrm",
      "cwe": "CWE-285",
      "title": "WACRM: Service-role routes missing a role check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77239"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-81179",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syslifters",
      "product": "sysreptor",
      "cwe": "CWE-807",
      "title": "SysReptor: Host header injection might allow account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81179"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-82892",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82892"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-84077",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-352",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84077"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-84081",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-295",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84081"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-84085",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84085"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-84108",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-79",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84108"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-84241",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-285",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84241"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-88097",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-416",
      "title": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88097"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-61721",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluidSynth",
      "product": "fluidsynth",
      "cwe": "CWE-122",
      "title": "FluidSynth: Heap-based buffer overrun for DLS samples",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61721"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-46655",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "virtio-win",
      "product": "kvm-guest-drivers-windows",
      "cwe": "CWE-122",
      "title": "virtio-win: Integer overflow causing a heap overflow in Viosock driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46655"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-61714",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluidSynth",
      "product": "fluidsynth",
      "cwe": "CWE-122",
      "title": "FluidSynth: Heap Buffer Overflow in MIDI Player",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61714"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-63419",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-787",
      "title": "OpenImageIO: IFF ZBUFFER tile read writes past caller tile buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63419"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-63422",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-122",
      "title": "OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63422"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-82893",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-269",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82893"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-84083",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-269",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84083"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-84089",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-269",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84089"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-81944",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET IGS-5225-8P2T4S V1",
      "cwe": "CWE-121",
      "title": "PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81944"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-84105",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84105"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-93872",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-502",
      "title": "Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93872"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-67549",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-122",
      "title": "OpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67549"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-82896",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-22",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82896"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-84076",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-285",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84076"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-84239",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-89",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84239"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2025-14753",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "IBM Cloud Pak for Data is vulnerable to path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14753"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-10744",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ for HPE NonStop",
      "cwe": "CWE-122",
      "title": "IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10744"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-10751",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-502",
      "title": "IBM MQ Java messaging is vulnerable to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10751"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-10853",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-470",
      "title": "IBM MQ queue manager is vulnerable to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10853"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-11716",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ for HPE NonStop",
      "cwe": "CWE-122",
      "title": "IBM MQ for HPE NonStop is vulnerable to a denial of service attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11716"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-32641",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parseablehq",
      "product": "parseable",
      "cwe": "CWE-248",
      "title": "Parseable: Unauthenticated Denial of Service via panic in Kinesis header parsing middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32641"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-57227",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57227"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-63446",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-401",
      "title": "Suricata app-layer: passed flows can retain transactions, causing resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63446"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-63447",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-407",
      "title": "Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63447"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-63452",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63452"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-69184",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "c-ares",
      "product": "c-ares",
      "cwe": "CWE-407",
      "title": "c-ares: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69184"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-71418",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-407",
      "title": "Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71418"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-77301",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cthackers",
      "product": "adm-zip",
      "cwe": "CWE-789",
      "title": "adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77301"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-81945",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET IGS-5225-8P2T4S V1",
      "cwe": "CWE-121",
      "title": "PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81945"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-84384",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-409",
      "title": "libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84384"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-84446",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-835",
      "title": "libheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84446"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-84447",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-770",
      "title": "libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84447"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-85058",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-862",
      "title": "Moquette: Missing Authorization in io.moquette:moquette-broker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85058"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-91149",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Cockpit: cockpit: denial of service via unbounded connection thread spawning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91149"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-92708",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "devalue",
      "cwe": "CWE-200",
      "title": "devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92708"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-93488",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-770",
      "title": "Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93488"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-93491",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-770",
      "title": "Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipeline queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93491"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-93558",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93558"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-93560",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93560"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-93563",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93563"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-93564",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93564"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-93565",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93565"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-93567",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-20",
      "title": "Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authority",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93567"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-93568",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-20",
      "title": "Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connect requests are downgraded as regular connect requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93568"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-93572",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-770",
      "title": "Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patched preallocation limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93572"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-93575",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93575"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-93576",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-93",
      "title": "Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93576"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-93652",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D3TN GmbH",
      "product": "µD3TN",
      "cwe": "CWE-190",
      "title": "Integer Overflow or Wraparound in µD3TN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93652"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-84036",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-285",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84036"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-84444",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-787",
      "title": "libheif uncompressed tiled image encoding allows out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84444"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-84975",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-295",
      "title": "PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84975"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-93658",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uutils",
      "product": "coreutils",
      "cwe": "CWE-281",
      "title": "uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93658"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-61552",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Icinga",
      "product": "icinga2",
      "cwe": "CWE-94",
      "title": "Icinga 2 DSL Injection via Unescaped Import Template Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61552"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-81669",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81669"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-81937",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81937"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-84071",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84071"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-84086",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-22",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84086"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-93591",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93591"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-93854",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Blazar",
      "cwe": "CWE-1025",
      "title": "In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it looks up the lease under the keyword \"lease_id\" whereas the controller methods name the parameter \"id\" (and the wsme_pecan.wsexpose wrapper delivers it positionally). The lookup returns None, and thus authorization falls back to the requesting user's own project_id/user_id instead of the target lease owner. Any authenticated user who knows a lease ID can therefore modify or delete leases belonging to other users and projects, bypassing the intended ownership check.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93854"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-10030",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ",
      "cwe": "CWE-285",
      "title": "IBM MQ Console is vulnerable to privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10030"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-61672",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcapsule",
      "product": "capsule",
      "cwe": "CWE-697",
      "title": "Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61672"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-62279",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hargata",
      "product": "lubelog",
      "cwe": "CWE-639",
      "title": "LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records from Any User's Vehicle Without Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62279"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-63445",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perses",
      "product": "perses",
      "cwe": "CWE-22",
      "title": "Perses: Unvalidated project parameter enables filesystem path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63445"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-63458",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perses",
      "product": "perses",
      "cwe": "CWE-639",
      "title": "Perses project query parameter authorization bypass exposes cross-project resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63458"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-77927",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77927"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-77928",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77928"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-81505",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frain-dev",
      "product": "convoy",
      "cwe": "CWE-639",
      "title": "Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81505"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-93594",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-863",
      "title": "ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93594"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-93595",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-862",
      "title": "ArcadeDB before 26.9.1 ACL Bypass via query_database Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93595"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-93598",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-184",
      "title": "ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93598"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-93660",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "SQLBot",
      "cwe": "CWE-639",
      "title": "SQLBot through 1.10.1 Improper Access Control via Dashboard Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93660"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-93737",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "azkaban",
      "product": "azkaban",
      "cwe": "CWE-862",
      "title": "Azkaban through 4.0.0 Authorization Bypass via ScheduleServlet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93737"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-93763",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-312",
      "title": "Silent plaintext persistence via unresolved callable database name in encryption schema map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93763"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-93764",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB Inc.",
      "product": "Mongoid",
      "cwe": "CWE-312",
      "title": "Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93764"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-93852",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Blazar",
      "cwe": "CWE-862",
      "title": "In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants, exposing lease IDs, reservation IDs, resource IDs, and reservation metadata. The exposed lease IDs also enable the object-level authorization bypass tracked in the companion request, allowing an attacker to then modify or delete the enumerated leases.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93852"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-7006",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sublime HQ Pty Ltd",
      "product": "Sublime Text 4",
      "cwe": "CWE-494",
      "title": "Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7006"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-57223",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-428",
      "title": "Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57223"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-63349",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agronholm",
      "product": "anyio",
      "cwe": "CWE-266",
      "title": "AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63349"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-73863",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-125",
      "title": "NanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRIBE Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73863"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-81305",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "HMT.CM2507 Firmware",
      "cwe": "CWE-829",
      "title": "CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81305"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-63646",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-200",
      "title": "CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63646"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-77396",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pjsip",
      "product": "pjproject",
      "cwe": "CWE-122",
      "title": "PJSIP: Heap buffer overflow in the AVI parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77396"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-77960",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bransys",
      "product": "ELD",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in Bransys ELD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77960"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-93338",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grandstream Networks",
      "product": "GWN7660ELR",
      "cwe": "CWE-1188",
      "title": "Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community String",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93338"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-93559",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forget-C",
      "product": "Jellyfish AI Short Drama Studio",
      "cwe": "CWE-287",
      "title": "Forget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93559"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-93604",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-284",
      "title": "vm2 3.11.8 Sandbox Escape via crypto.setFips",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93604"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-93751",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "garycourt",
      "product": "uri-js",
      "cwe": "CWE-176",
      "title": "uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93751"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-61722",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluidSynth",
      "product": "fluidsynth",
      "cwe": "CWE-190",
      "title": "FluidSynth: DLS Articulation Chunk Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61722"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-61723",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluidSynth",
      "product": "fluidsynth",
      "cwe": "CWE-190",
      "title": "FluidSynth: DLS ptbl Chunk Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61723"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-61794",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcapsule",
      "product": "capsule",
      "cwe": "CWE-20",
      "title": "Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61794"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-61795",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcapsule",
      "product": "capsule",
      "cwe": "CWE-697",
      "title": "Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61795"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-64847",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agronholm",
      "product": "anyio",
      "cwe": "CWE-770",
      "title": "AnyIO process-pool workers can block indefinitely on undrained stderr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64847"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-75883",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PPP Project",
      "product": "ppp",
      "cwe": "CWE-122",
      "title": "PPPD buffer overflow in PEAP response code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75883"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-76900",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-918",
      "title": "CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76900"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-77875",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QUANTUMTECH LTD",
      "product": "Hide Photos - Secure vault",
      "cwe": "CWE-922",
      "title": "Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77875"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-93689",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "winfsp",
      "product": "winfsp",
      "cwe": "CWE-476",
      "title": "WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93689"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-81627",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81627"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-81946",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PLANET Technology Corp.",
      "product": "PLANET IGS-5225-8P2T4S V1",
      "cwe": "CWE-121",
      "title": "PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81946"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2025-33141",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "QRadar",
      "cwe": "CWE-497",
      "title": "IBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33141"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-11549",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "CICS TX Advanced",
      "cwe": "CWE-284",
      "title": "Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11549"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-11710",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11710"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-11711",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-502",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11711"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-54147",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4k",
      "product": "http4k",
      "cwe": "CWE-327",
      "title": "http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54147"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-57224",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57224"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-59156",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-674",
      "title": "OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59156"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-61670",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "superradcompany",
      "product": "microsandbox",
      "cwe": "CWE-214",
      "title": "microsandbox: Secret values exposed in world-readable process arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61670"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-61822",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgpartman",
      "product": "pg_partman",
      "cwe": "CWE-703",
      "title": "pg_partman disable maintenance for all partition sets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61822"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-62282",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opencve",
      "product": "opencve",
      "cwe": "CWE-918",
      "title": "OpenCVE: Server-Side Request Forgery (SSRF) in notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62282"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-71537",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymenter",
      "product": "Paymenter",
      "cwe": "CWE-362",
      "title": "Paymenter: Credit-refund double-spend race condition in service downgrade (doUpgrade)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71537"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-77386",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zoriya",
      "product": "Kyoo",
      "cwe": "CWE-601",
      "title": "Kyoo: OIDC login token can be redirected to an attacker-controlled URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77386"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-84451",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84451"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-93561",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93561"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-93562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93562"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-93566",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93566"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-93573",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-444",
      "title": "Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked validation and enable request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93573"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-93574",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-444",
      "title": "Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in chunk-size parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93574"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-93579",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93579"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-18869",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-918",
      "title": "IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18869"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-81623",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-78",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81623"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-93589",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-369",
      "title": "ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93589"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-93590",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93590"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-93840",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-129",
      "title": "vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93840"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-93841",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-129",
      "title": "vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93841"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-61720",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluidSynth",
      "product": "fluidsynth",
      "cwe": "CWE-191",
      "title": "FluidSynth: SF2 DMOD Chunk Unsigned Underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61720"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2025-36147",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager for SWIFT Services for Multiplatforms",
      "cwe": "CWE-79",
      "title": "IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to cross-site scripting.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36147"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-1025",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1025"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-1031",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1031"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-1037",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1037"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-59181",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-121",
      "title": "OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59181"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-59956",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-125",
      "title": "OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59956"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-77606",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SemanticMediaWiki",
      "product": "SemanticMediaWiki",
      "cwe": "CWE-79",
      "title": "Semantic MediaWiki has reflected XSS in Special:Ask plain table headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77606"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-77607",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SemanticMediaWiki",
      "product": "SemanticMediaWiki",
      "cwe": "CWE-79",
      "title": "Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77607"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-77608",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SemanticMediaWiki",
      "product": "SemanticMediaWiki",
      "cwe": "CWE-79",
      "title": "Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77608"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-77609",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SemanticMediaWiki",
      "product": "SemanticMediaWiki",
      "cwe": "CWE-601",
      "title": "Semantic MediaWiki has an open redirect in Special:URIResolver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77609"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-77610",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SemanticMediaWiki",
      "product": "SemanticMediaWiki",
      "cwe": "CWE-79",
      "title": "Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77610"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-77616",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SemanticMediaWiki",
      "product": "SemanticMediaWiki",
      "cwe": "CWE-79",
      "title": "Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77616"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-79294",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79294"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-84992",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imzbf",
      "product": "md-editor-v3",
      "cwe": "CWE-79",
      "title": "md-editor-v3: XSS via fenced-code language rendering bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84992"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-85271",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openedx",
      "product": "openedx-platform",
      "cwe": "CWE-79",
      "title": "Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thread Title (incomplete patch of CVE-2026-42857)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85271"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-91202",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-61",
      "title": "Cockpit-files: cockpit-files: arbitrary file ownership change via symlink following in privileged paste",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91202"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-93432",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Exploit Intelligence",
      "cwe": "CWE-79",
      "title": "Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection via qute {#eval} section in quarkus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93432"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-91203",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-363",
      "title": "Cockpit-files: cockpit-files: arbitrary file ownership and permission modification via symlink race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91203"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-91205",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-363",
      "title": "Cockpit-files: cockpit-files: local attacker can hijack file ownership via symlink race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91205"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2024-56344",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cognos Analytics",
      "cwe": "CWE-327",
      "title": "IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-56344"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2025-33147",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cognos Analytics",
      "cwe": "CWE-327",
      "title": "IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33147"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2025-36421",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Controller",
      "cwe": "CWE-319",
      "title": "Multiple vulnerabilities in IBM Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36421"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-10832",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Cryostat 4",
      "cwe": "CWE-770",
      "title": "Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10832"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-63405",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anycable",
      "product": "anycable",
      "cwe": "CWE-345",
      "title": "AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63405"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-63406",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anycable",
      "product": "anycable",
      "cwe": "CWE-312",
      "title": "AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63406"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-63448",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-400",
      "title": "Suricata smb: some SMB flows can cause resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63448"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-71855",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-697",
      "title": "Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71855"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-82890",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-79",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82890"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-91147",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-617",
      "title": "Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91147"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-93578",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel for Spring Boot 4",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93578"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-93602",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustls",
      "product": "webpki",
      "cwe": "CWE-299",
      "title": "rustls-webpki before 0.103.10 CRL Revocation Check Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93602"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-76901",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-639",
      "title": "CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76901"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-76899",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-89",
      "title": "CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76899"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-63420",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-125",
      "title": "OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63420"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-63635",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-125",
      "title": "OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read and allocation DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63635"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-65969",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-125",
      "title": "OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65969"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-92768",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-214",
      "title": "Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92768"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-93653",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-606",
      "title": "Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93653"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2025-36178",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Controller",
      "cwe": "CWE-1284",
      "title": "Multiple vulnerabilities in IBM Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36178"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-1029",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1029"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-17262",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-78",
      "title": "IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17262"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-93685",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Management for Kubernetes 2",
      "cwe": "CWE-200",
      "title": "Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93685"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2025-1350",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Controller",
      "cwe": "CWE-209",
      "title": "Multiple vulnerabilities in IBM Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1350"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2025-13882",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling Partner Engagement Manager Essentials Edition",
      "cwe": "CWE-799",
      "title": "Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13882"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-11539",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-306",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11539"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-11540",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-863",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11540"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-52745",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-89",
      "title": "CordysCRM: Customer Public Pool Sorting Field SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52745"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-57222",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-697",
      "title": "Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57222"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-57229",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-665",
      "title": "Suricata smtp/mime: incomplete state reset allows detection bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57229"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-65970",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenImageIO",
      "cwe": "CWE-825",
      "title": "OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_native_scanlines`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65970"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-69186",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "c-ares",
      "product": "c-ares",
      "cwe": "CWE-400",
      "title": "c-ares: Memory-amplification denial of service via unvalidated DNS header record counts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69186"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-77528",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crossbario",
      "product": "autobahn-python",
      "cwe": "CWE-409",
      "title": "Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77528"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-93492",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat AMQ Broker 7",
      "cwe": "CWE-1035",
      "title": "Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93492"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-93504",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SveltyCMS",
      "cwe": "CWE-266",
      "title": "SveltyCMS User Attribute Update Endpoint +server.ts access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93504"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-93506",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SveltyCMS",
      "cwe": "CWE-918",
      "title": "SveltyCMS File Upload Endpoint upload-media server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93506"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-93533",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spatie",
      "product": "Scotty",
      "cwe": "CWE-77",
      "title": "spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93533"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-93534",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spatie",
      "product": "Scotty",
      "cwe": "CWE-494",
      "title": "spatie Scotty Self Update SelfUpdater.php update code download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93534"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-93596",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-862",
      "title": "ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93596"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-93597",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-918",
      "title": "ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93597"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-93736",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mealie-recipes",
      "product": "mealie",
      "cwe": "CWE-639",
      "title": "Mealie before 3.21.0 Information Disclosure via Ratings Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93736"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-93869",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-601",
      "title": "Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93869"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-93870",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93870"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-93873",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93873"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-93921",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93921"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-77339",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F1bonacc1",
      "product": "process-compose",
      "cwe": "CWE-306",
      "title": "Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77339"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-93505",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SveltyCMS",
      "cwe": "CWE-79",
      "title": "SveltyCMS SVG Media Upload media-service.server.ts cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93505"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-93871",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-601",
      "title": "Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93871"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-76902",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-306",
      "title": "CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76902"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-92745",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-214",
      "title": "Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92745"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-92747",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-214",
      "title": "Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92747"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-11548",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "CICS TX Advanced",
      "cwe": "CWE-444",
      "title": "Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11548"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-11722",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "CICS TX Advanced",
      "cwe": "CWE-444",
      "title": "Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11722"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-28199",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cohesity",
      "product": "NetBackup Flex OS",
      "cwe": "CWE-347",
      "title": "Sensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS Shell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28199"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-93587",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93587"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-16515",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-406",
      "title": "ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16515"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-25684",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zscaler",
      "product": "ZIA File Type Control",
      "cwe": "CWE-20",
      "title": "File Type Control rule bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25684"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2025-36045",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "TS4300",
      "cwe": "CWE-799",
      "title": "TS4300 Tape Library addresses security vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36045"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2025-36076",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cognos Analytics",
      "cwe": "CWE-540",
      "title": "IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36076"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-1030",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Common Licensing",
      "cwe": "CWE-209",
      "title": "Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1030"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-11537",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-650",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11537"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-16514",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16514"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-77385",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zoriya",
      "product": "Kyoo",
      "cwe": "CWE-639",
      "title": "Kyoo: Transcoder serves uncataloged files from the media directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77385"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-84450",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-617",
      "title": "libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84450"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-85272",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openedx",
      "product": "openedx-platform",
      "cwe": "CWE-22",
      "title": "Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85272"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-10841",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "CICS TX Advanced",
      "cwe": "CWE-444",
      "title": "Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10841"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-77568",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mojolicious",
      "product": "mojo",
      "cwe": "CWE-200",
      "title": "Mojolicious: CSRF tokens are vulnerable to BREACH attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77568"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-81182",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syslifters",
      "product": "sysreptor",
      "cwe": "CWE-639",
      "title": "SysReptor: Unauthorized file disclosure by broken access control in writable shared notes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81182"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-85511",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 7",
      "cwe": "CWE-290",
      "title": "Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85511"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-84448",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84448"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-11538",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-117",
      "title": "IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11538"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-11545",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-862",
      "title": "IBM WebSphere Application Server is affected by a privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11545"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-44639",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-407",
      "title": "NanoMQ: O(N²) Denial of Service in MQTT v5 Property Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44639"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-57226",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-122",
      "title": "Suricata swf: heap buffer overflow in SWF decompression depth handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57226"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-63449",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-197",
      "title": "Suricata sip: large SIP message bodies can evade detection with frame keyword",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63449"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-63450",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-755",
      "title": "Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63450"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-81181",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syslifters",
      "product": "sysreptor",
      "cwe": "CWE-384",
      "title": "SysReptor: Session Fixation in Password-Protected Shared Notes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81181"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-84449",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84449"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-91142",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91142"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-81178",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syslifters",
      "product": "sysreptor",
      "cwe": "CWE-863",
      "title": "SysReptor: Anonymous note-share link discloses project member identities and non-shared note activity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81178"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-57225",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-476",
      "title": "Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57225"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-63451",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "suricata",
      "cwe": "CWE-122",
      "title": "Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63451"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-93676",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-284",
      "title": "Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93676"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-16512",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16512"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-21806",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL BigFix  Service Management",
      "cwe": "CWE-557",
      "title": "HCL BigFix Service Management was affected with Admin Session Concurrency vulnerability (CVE-2026-21806)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21806"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-93650",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Saleor",
      "cwe": "CWE-307",
      "title": "Saleor throttling.py get_client_ip excessive authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93650"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-85478",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "HMT.CM2507 Firmware",
      "cwe": "CWE-306",
      "title": "CareCam CM2507 Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85478"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-84400",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CareCam",
      "product": "HMT.CM2507 Firmware",
      "cwe": "CWE-306",
      "title": "CareCam CM2507 Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84400"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-93588",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-476",
      "title": "ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93588"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-93894",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vinyl-Cache",
      "product": "Vinyl Cache",
      "cwe": "CWE-787",
      "title": "In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault or assert, and then restart. Effectively exploiting this vulnerability requires prior knowledge about the VCL in use and the ability to craft a request that contains a string that is long enough to fill the remaining workspace at the call site while staying under the different request size limits (http_req_size, http_req_hdr_len, etc.).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93894"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-93531",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-352",
      "title": "gedelumbung HospitalManagement cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93531"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-93532",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gedelumbung",
      "product": "HospitalManagement",
      "cwe": "CWE-287",
      "title": "gedelumbung HospitalManagement Password Change password.php simpan improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93532"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-93586",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93586"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-93600",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustls",
      "product": "webpki",
      "cwe": "CWE-295",
      "title": "rustls webpki Name Constraints URI Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93600"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-93601",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustls",
      "product": "webpki",
      "cwe": "CWE-295",
      "title": "rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93601"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-61633",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-835",
      "title": "NanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61633"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-75892",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Osmocom",
      "product": "osmo-ggsn",
      "cwe": "CWE-787",
      "title": "Out of bounds write in PDP ctx GSN-Address decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75892"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-75893",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Osmocom",
      "product": "osmo-bsc",
      "cwe": "CWE-122",
      "title": "Heap based buffer overflow at ipaccess_proxy_read_msg()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75893"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-75894",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Osmocom",
      "product": "osmo-iuh",
      "cwe": "CWE-617",
      "title": "Reachable assertion at ranap_handle_co_dt()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75894"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-75895",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Osmocom",
      "product": "libsmpp34",
      "cwe": "CWE-125",
      "title": "Out of bounds read at smpp34_unpack()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75895"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-88623",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This operation requires no authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88623"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-93018",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Imager",
      "cwe": "CWE-193",
      "title": "Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93018"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2025-39682",
      "detail": "ADDED TO KEV — CVE-2025-39682 (Linux). Remediation due September 21, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2025-39964",
      "detail": "ADDED TO KEV — CVE-2025-39964 (Linux). Remediation due September 21, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-53266",
      "detail": "ADDED TO KEV — CVE-2026-53266 (Linux). Remediation due September 21, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-6021",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41424",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41424 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42578 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42579",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42579 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42581",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42584",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42584 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44252",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44252 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44254",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44254 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44255 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44256",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44256 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46343",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46343 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66046",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66046 (libexpat project libexpat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70479",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70479 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70480",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70480 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70481",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70481 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70482",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70482 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70483",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70483 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70485",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70485 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70486 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70489",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70489 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70491",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70491 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70492 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70493",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70493 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86176",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86176 (netbox-community netbox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86426",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86426 (librenms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86427",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86427 (librenms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86739",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86739 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86744",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86744 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87819",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87819 (gitpython-developers GitPython). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87886",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87928",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87928 (MaxSite CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89034",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89034 (TCH QRing). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89044 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90489",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90489 (Xuxueli xxl-job). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90801",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90801 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90802",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90802 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90803",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90803 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90804",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90804 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91732",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91732 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91995",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91995 (pig-mesh pig). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92381",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92381 (PbootCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92399",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92399 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92413",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92413 (Artifex MuPDF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92458",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92458 (guchengwuyue yshop-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92463",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92463 (guchengwuyue yshop-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92468",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92468 (zlt2000 microservices-platform). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92473",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92473 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92776",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92776 (requarks Wiki.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92800",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92800 (suitenumerique Docs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92812 (decaporg decap-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92921",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92921 (cjbi admin3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92926",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92926 (code-projects Matrimonial System). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-76461",
      "detail": "DUE DATE PASSED — CVE-2026-76461 (Cisco Secure Email). CISA remediation deadline was September 17, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-10072",
      "detail": "RESCORED — CVE-2025-10072 (Portabilis i-Educar). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12645",
      "detail": "RESCORED — CVE-2026-12645 (Ivanti Neurons for ITSM). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12646",
      "detail": "RESCORED — CVE-2026-12646 (Ivanti Neurons for ITSM). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12647",
      "detail": "RESCORED — CVE-2026-12647 (Ivanti Neurons for ITSM). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12650",
      "detail": "RESCORED — CVE-2026-12650 (Ivanti Neurons for ITSM). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70482",
      "detail": "RESCORED — CVE-2026-70482 (open-webui). CVSS 8.1 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70483",
      "detail": "RESCORED — CVE-2026-70483 (open-webui). CVSS 3.1 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70484",
      "detail": "RESCORED — CVE-2026-70484 (open-webui). CVSS 4.3 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70486",
      "detail": "RESCORED — CVE-2026-70486 (open-webui). CVSS 8.2 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70487",
      "detail": "RESCORED — CVE-2026-70487 (open-webui). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70492",
      "detail": "RESCORED — CVE-2026-70492 (open-webui). CVSS 8.7 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-84566",
      "detail": "RESCORED — CVE-2026-84566 (Apple iOS and iPadOS). CVSS 8.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-85544",
      "detail": "RESCORED — CVE-2026-85544 (Hikvision DS-KV9503). CVSS 5.2 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-91719",
      "detail": "RESCORED — CVE-2026-91719 (Google Chrome). CVSS 4.3 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-91723",
      "detail": "RESCORED — CVE-2026-91723 (Google Chrome). CVSS 4.2 → 3.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-91732",
      "detail": "RESCORED — CVE-2026-91732 (Google Chrome). CVSS 3.1 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-93308",
      "detail": "RESCORED — CVE-2026-93308 (O-RAN-SC SMO OAM). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-93309",
      "detail": "RESCORED — CVE-2026-93309 (O-RAN-SC SMO OAM). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-90168",
      "detail": "REJECTED — CVE-2026-90168 (Linux). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-90310",
      "detail": "REJECTED — CVE-2026-90310 (Linux). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-65490",
      "detail": "PATCH SHIPPED — CVE-2026-65490 (John-Michael L'Allier Create). Fixed in Create 2.6.1."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2018-13410",
      "detail": "ENRICHED — CVE-2018-13410. Received CVSS 9.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
