{
  "day": "2026-09-20",
  "boundary": "UTC calendar day",
  "published_count": 105,
  "by_severity": {
    "CRITICAL": 12,
    "HIGH": 17,
    "MEDIUM": 43,
    "LOW": 33
  },
  "kev_count": 0,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-93958",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02175,
      "epss_percentile": 0.81518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "R95",
      "cwe": "CWE-77",
      "title": "D-Link R95 DHMAPI ssi system os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93958"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-93965",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01573,
      "epss_percentile": 0.74302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aiyiyi121",
      "product": "SxDevOps",
      "cwe": "CWE-74",
      "title": "aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93965"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-93966",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01573,
      "epss_percentile": 0.74302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aiyiyi121",
      "product": "SxDevOps",
      "cwe": "CWE-74",
      "title": "aiyiyi121 SxDevOps TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93966"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-93967",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00726,
      "epss_percentile": 0.52617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aiyiyi121",
      "product": "SxDevOps",
      "cwe": "CWE-74",
      "title": "aiyiyi121 SxDevOps Command services.py generate_host_task command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93967"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-93962",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00529,
      "epss_percentile": 0.43676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Kamailio",
      "cwe": "CWE-119",
      "title": "Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93962"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-86553",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.38144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "SmartLife",
      "cwe": "CWE-269",
      "title": "A password reset vulnerability in ZTE SmartLife APP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86553"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-93961",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0042,
      "epss_percentile": 0.35908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "UJCMS",
      "cwe": "CWE-266",
      "title": "Dromara UJCMS UserController UserController.java usernameExist improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93961"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-94083",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.34191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "Suricata",
      "cwe": "CWE-843",
      "title": "Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94083"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-94084",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.34191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OISF",
      "product": "Suricata",
      "cwe": "CWE-416",
      "title": "Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94084"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-93975",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00368,
      "epss_percentile": 0.30648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Assessment Management",
      "cwe": "CWE-79",
      "title": "code-projects Assessment Management User Editing edit-user.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93975"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-93960",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00366,
      "epss_percentile": 0.3043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Pixelfed",
      "cwe": "CWE-287",
      "title": "Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93960"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-93959",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.29347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93959"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-93974",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.2617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php remove sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93974"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-93971",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aiyiyi121",
      "product": "SxDevOps",
      "cwe": "CWE-200",
      "title": "aiyiyi121 SxDevOps settings.py information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93971"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-93957",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00299,
      "epss_percentile": 0.22765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "olivier-ls",
      "product": "PHP-FTS",
      "cwe": "CWE-697",
      "title": "olivier-ls PHP-FTS Filter Matching SearchEngine.php matchesSingleFilter comparison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93957"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-93969",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aiyiyi121",
      "product": "SxDevOps",
      "cwe": "CWE-259",
      "title": "aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93969"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-93970",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aiyiyi121",
      "product": "SxDevOps",
      "cwe": "CWE-259",
      "title": "aiyiyi121 SxDevOps Settings settings.py hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93970"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-93964",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NginxProxyManager",
      "product": "nginx-proxy-manager",
      "cwe": "CWE-287",
      "title": "NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93964"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-93972",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93972"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-86552",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "SmartLife",
      "cwe": "CWE-269",
      "title": "A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86552"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-93973",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php remove sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93973"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-93968",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.1766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aiyiyi121",
      "product": "SxDevOps",
      "cwe": "CWE-266",
      "title": "aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93968"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-86555",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "SmartLife",
      "cwe": "CWE-798",
      "title": "Hardcoded Key Vulnerability in ZTE SmartLife APP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86555"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-93963",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System controller.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93963"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-86554",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "SmartLife",
      "cwe": "CWE-269",
      "title": "Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86554"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-86551",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.06836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "NX741J",
      "cwe": "CWE-668",
      "title": "Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX741J) product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86551"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-87067",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Forminator Forms",
      "cwe": "CWE-94",
      "title": "Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87067"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-14844",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Master Slider",
      "cwe": "CWE-79",
      "title": "Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14844"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-84223",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-79",
      "title": "Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84223"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-85017",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unlimited Elements For Elementor",
      "cwe": "CWE-502",
      "title": "Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85017"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-81650",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Photo Gallery, Sliders, Proofing and Themes",
      "cwe": "CWE-434",
      "title": "NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81650"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-92423",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00139,
      "epss_percentile": 0.03674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Meow Gallery",
      "cwe": "CWE-200",
      "title": "Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92423"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-87839",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tripzzy",
      "cwe": "CWE-284",
      "title": "Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87839"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-87840",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tripzzy",
      "cwe": "CWE-284",
      "title": "Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87840"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-82842",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SAML Single Sign On",
      "cwe": "CWE-269",
      "title": "SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82842"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-92540",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Import and export users and customers",
      "cwe": "CWE-269",
      "title": "Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92540"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-92541",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Import and export users and customers",
      "cwe": "CWE-269",
      "title": "Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92541"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-87068",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Forminator Forms",
      "cwe": "CWE-269",
      "title": "Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87068"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-81653",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Photo Gallery, Sliders, Proofing and Themes",
      "cwe": "CWE-639",
      "title": "NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81653"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-16542",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Import and export users and customers",
      "cwe": "CWE-918",
      "title": "Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16542"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-92965",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TikTok",
      "cwe": "CWE-862",
      "title": "TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92965"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-81651",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Photo Gallery, Sliders, Proofing and Themes",
      "cwe": "CWE-639",
      "title": "NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81651"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-81654",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Photo Gallery, Sliders, Proofing and Themes",
      "cwe": "CWE-639",
      "title": "NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81654"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-81652",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Photo Gallery, Sliders, Proofing and Themes",
      "cwe": "CWE-639",
      "title": "NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81652"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-92422",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Meow Gallery",
      "cwe": "CWE-345",
      "title": "Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92422"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-92410",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Sign-up Sheets",
      "cwe": "CWE-352",
      "title": "Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92410"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-94097",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-77",
      "title": "Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94097"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-90817",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vanderbilt University",
      "product": "REDCap",
      "cwe": "CWE-73",
      "title": "An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90817"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-88856",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OrdaSoft.com",
      "product": "OrdaSoft Joomla Gallery free extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88856"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-88857",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OrdaSoft.com",
      "product": "OrdaSoft Joomla Gallery free extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88857"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-94095",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-77",
      "title": "Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94095"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-94096",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-77",
      "title": "Netcore NBR200V2 LAN IP Configuration network_tools command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94096"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-88854",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OrdaSoft.com",
      "product": "OrdaSoft Joomla Gallery free extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88854"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-94003",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfast",
      "product": "CF-N1-S",
      "cwe": "CWE-119",
      "title": "Comfast CF-N1-S Web Management mbox-config get_css_path_from_uri stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94003"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-94089",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-868L",
      "cwe": "CWE-119",
      "title": "D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94089"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-94107",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nivocart",
      "product": "nivocart",
      "cwe": "CWE-338",
      "title": "NivoCart through 2.4.0 Predictable Administrator Password Reset Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94107"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-94104",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nivocart",
      "product": "nivocart",
      "cwe": "CWE-434",
      "title": "NivoCart through 2.4.0 Arbitrary File Upload RCE via filemanager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94104"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-94106",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "james-heinrich",
      "product": "getid3",
      "cwe": "CWE-78",
      "title": "getID3 before 1.9.26 OS Command Injection via Unescaped Filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94106"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-94109",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openequella",
      "product": "openEQUELLA",
      "cwe": "CWE-1336",
      "title": "openEQUELLA before 2026.1.0 Remote Code Execution via FreeMarker Template Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94109"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-88855",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OrdaSoft.com",
      "product": "OrdaSoft Joomla Gallery free extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88855"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-94108",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "james-heinrich",
      "product": "getid3",
      "cwe": "CWE-611",
      "title": "getID3 through 1.9.26 XML External Entity Injection via XML2array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94108"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-94112",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mayswind",
      "product": "ezBookkeeping",
      "cwe": "CWE-294",
      "title": "mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94112"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-94036",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-X1860",
      "cwe": "CWE-266",
      "title": "D-Link DIR-X1860/DIR-X1860Z routerd ubus access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94036"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-94113",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "ERPNext",
      "cwe": "CWE-862",
      "title": "Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94113"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-92254",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Watchdog",
      "product": "Anti-Virus",
      "cwe": "CWE-20",
      "title": "WatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated IOCTL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92254"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-94105",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nivocart",
      "product": "nivocart",
      "cwe": "CWE-754",
      "title": "NivoCart through 2.4.0 Destructive Configuration Write via the Password Reset Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94105"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-94111",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tencent",
      "product": "BrowserSkill",
      "cwe": "CWE-346",
      "title": "Tencent BrowserSkill through 0.3.0 Origin Validation Error in Local WebSocket Daemon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94111"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-92252",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchDog",
      "product": "Anti-Virus",
      "cwe": "CWE-276",
      "title": "Incorrect Default Permissions in WatchDog Anti-Virus Installation Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92252"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-93978",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Internship Management System",
      "cwe": "CWE-74",
      "title": "code-projects Internship Management System login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93978"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-93979",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Internship Management System",
      "cwe": "CWE-74",
      "title": "code-projects Internship Management System login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93979"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-93980",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Internship Management System",
      "cwe": "CWE-74",
      "title": "code-projects Internship Management System Admin Login Form login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93980"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-93997",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-74",
      "title": "SourceCodester Drug Recommendation System edit_symptom.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93997"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-94004",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DedeCMS",
      "cwe": "CWE-74",
      "title": "DedeCMS mytag_js.php code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94004"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-94015",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-74",
      "title": "SourceCodester Drug Recommendation System edit_user.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94015"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-94038",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NonceGeek",
      "product": "dim-sum-app",
      "cwe": "CWE-918",
      "title": "NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94038"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-94039",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vas3k",
      "product": "TaxHacker",
      "cwe": "CWE-918",
      "title": "vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94039"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-94040",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vas3k",
      "product": "TaxHacker",
      "cwe": "CWE-918",
      "title": "vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94040"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-94043",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Free5GC",
      "cwe": "CWE-362",
      "title": "Free5GC Gmm handler.go race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94043"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-94044",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "03-lovepreetSingh",
      "product": "MCP",
      "cwe": "CWE-22",
      "title": "03-lovepreetSingh MCP route.ts create_file path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94044"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-94050",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-X1860Z",
      "cwe": "CWE-200",
      "title": "D-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94050"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-94090",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JusticeRage",
      "product": "Manalyze",
      "cwe": "CWE-189",
      "title": "JusticeRage Manalyze PE Parser pe.cpp _parse_debug integer underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94090"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-92253",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchDog",
      "product": "Anti-Virus",
      "cwe": "CWE-59",
      "title": "Arbitrary File Write via Directory Junction in WatchDog Anti-Virus Quarantine Restoration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92253"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-94028",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mealie-recipes",
      "product": "Mealie",
      "cwe": "CWE-918",
      "title": "mealie-recipes Mealie Recipe Action Trigger controller_group_recipe_actions.py payload.model_dump server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94028"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-94031",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0-Gaurav-0",
      "product": "nexus-mcp",
      "cwe": "CWE-74",
      "title": "0-Gaurav-0 nexus-mcp nexus_reauth MCP tool browser.ts child_process.exec command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94031"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-94032",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Leave Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94032"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-94035",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-79",
      "title": "SourceCodester Drug Recommendation System index.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94035"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-94037",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "00Kisumi00",
      "product": "mcp-file-analyzer",
      "cwe": "CWE-22",
      "title": "00Kisumi00 mcp-file-analyzer analyze_csv_data MCP tool main.py ControlFlowNode path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94037"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-94041",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant-Management-System",
      "cwe": "CWE-74",
      "title": "AdithyaYelloju Restaurant-Management-System add_menu.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94041"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-94042",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant Management System",
      "cwe": "CWE-74",
      "title": "AdithyaYelloju Restaurant Management System add_table.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94042"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-94046",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0215AndrewFeng",
      "product": "ACE-MCP",
      "cwe": "CWE-22",
      "title": "0215AndrewFeng ACE-MCP MCP Tool getFileSnippet.ts get_file_snippet path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94046"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-94047",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samanhappy",
      "product": "MCPHub",
      "cwe": "CWE-266",
      "title": "samanhappy MCPHub Template Import Endpoint templateService.ts importTemplate privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94047"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-94049",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "06ketan",
      "product": "slideshot",
      "cwe": "CWE-22",
      "title": "06ketan slideshot renderer.ts render_slides path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94049"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-94051",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "0717376",
      "product": "cowork_bench",
      "cwe": "CWE-918",
      "title": "0717376 cowork_bench pdf-tools-mcp server.py ControlFlowNode server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94051"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-94093",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DLR-RM",
      "product": "stable-baselines3",
      "cwe": "CWE-20",
      "title": "DLR-RM stable-baselines3 save_util.py VecNormalize.load deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94093"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-94094",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenClaw",
      "cwe": "CWE-404",
      "title": "OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94094"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-93977",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Assessment Management",
      "cwe": "CWE-79",
      "title": "code-projects Assessment Management add-single-mark.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93977"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-94033",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-79",
      "title": "SourceCodester Drug Recommendation System User Management add_user cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94033"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-94034",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-79",
      "title": "SourceCodester Drug Recommendation System Password Change change_password cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94034"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-94045",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "newbee-ltd",
      "product": "newbee-mall",
      "cwe": "CWE-79",
      "title": "newbee-ltd newbee-mall Goods Save Endpoint UploadController.java cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94045"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-94048",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "QR Code Attendance Management System",
      "cwe": "CWE-266",
      "title": "CodeAstro QR Code Attendance Management System UserController.php save privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94048"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-94091",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "piskvorky",
      "product": "gensim",
      "cwe": "CWE-20",
      "title": "piskvorky gensim Model Loader utils.py load deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94091"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-94092",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dmlc",
      "product": "dgl",
      "cwe": "CWE-20",
      "title": "dmlc dgl utils.py _read_torch_data deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94092"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-93976",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Assessment Management",
      "cwe": "CWE-79",
      "title": "code-projects Assessment Management add-user.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93976"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-94016",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Drug Recommendation System",
      "cwe": "CWE-79",
      "title": "SourceCodester Drug Recommendation System add_symptom cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94016"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-94030",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SerenityOS",
      "cwe": "CWE-189",
      "title": "SerenityOS LibGfx BMPLoader.cpp decode_bmp_pixel_data integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94030"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86754",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86754 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86759",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86759 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86764 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86769",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86769 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86774 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87963",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87963 (Unknown Yo). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-58704",
      "detail": "DUE DATE PASSED — CVE-2026-58704 (Google Android). CISA remediation deadline was September 19, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-76460",
      "detail": "DUE DATE PASSED — CVE-2026-76460 (Cisco Identity Services Engine Software). CISA remediation deadline was September 19, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-87886",
      "detail": "DUE DATE PASSED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). CISA remediation deadline was September 19, 2026; still in catalog."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-12564",
      "detail": "PATCH SHIPPED — CVE-2026-12564 (Red Hat Ansible Automation Platform 2.7). Fixed in Red Hat Ansible Automation Platform 2.7 1788918363."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-32551",
      "detail": "PATCH SHIPPED — CVE-2026-32551 (DiviNext Woo Essential). Fixed in Woo Essential 4.3.1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-42784",
      "detail": "PATCH SHIPPED — CVE-2026-42784 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 0.3.2-4.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71576",
      "detail": "PATCH SHIPPED — CVE-2026-71576 (Red Hat Multicluster Global Hub 1.4.9). Fixed in Multicluster Global Hub 1.4.9 1788355599."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-81796",
      "detail": "PATCH SHIPPED — CVE-2026-81796 (WEN Solutions WP Travel). Fixed in WP Travel 12.0.4."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
