{
  "day": "2026-09-21",
  "boundary": "UTC calendar day",
  "published_count": 286,
  "by_severity": {
    "CRITICAL": 15,
    "HIGH": 113,
    "MEDIUM": 108,
    "LOW": 28
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 22,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-94098",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02385,
      "epss_percentile": 0.83038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-74",
      "title": "Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94098"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-94138",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.02055,
      "epss_percentile": 0.80165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chengdu Feiyuxing Technology",
      "product": "Feiyu Star Router",
      "cwe": "CWE-74",
      "title": "Chengdu Feiyuxing Technology Feiyu Star Router send_order.cgi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94138"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-94099",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01687,
      "epss_percentile": 0.75637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-74",
      "title": "Netcore NBR200V2 Backup Restore restore.cgi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94099"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-94139",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.65219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chengdu Feiyuxing Technology",
      "product": "Feiyu Star Router",
      "cwe": "CWE-74",
      "title": "Chengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94139"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-94100",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.38672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-119",
      "title": "Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94100"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-94101",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcore",
      "product": "NBR200V2",
      "cwe": "CWE-119",
      "title": "Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94101"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2025-12999",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.34452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Open VSX",
      "cwe": null,
      "title": "UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a trusted proxy, falling back to the client-supplied Host header. Those responses are cached under keys that do not include the host (extension.json since 0.6.0, namespace.details.json since 0.9.0, sitemap since 0.14.5, latest.extension.version.vscode since 0.34.2). A single request carrying a forged header therefore places attacker-chosen URLs into an entry served to every other client for the lifetime of that entry — one hour by default, and cluster-wide where ovsx.redis.enabled is set. The VSIX download URL, its signature URL and the public key URL are all derived from the same base URL, so extension signing does not limit the impact: an attacker who poisons an entry supplies the package, the signature over it, and the key used to verify it. Exploitability depends on deployment topology. A server reachable directly by clients, or fronted by a proxy that relays the client's X-Forwarded-Host rather than overwriting it, is exploitable by an unauthenticated remote attacker. A proxy that overwrites the header is not. An unauthenticated attacker can poison Open VSX's per-extension metadata cache with attacker-controlled download, signature, and public-key URLs by supplying a crafted X-Forwarded-Host header, causing downstream VS Code-compatible editors to fetch and install a malicious VSIX. Workarounds (unpatched versions) 1. Configure the reverse proxy to set rather than relay X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix — note that nginx's $host is the client's Host header and is not a safe value. 2. Ensure the server is not reachable except through that proxy. 3. Flush the caches afterwards; poisoned entries survive the configuration change.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12999"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-94151",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.3339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "HRM OS",
      "cwe": "CWE-287",
      "title": "Omega Solution HRM OS Role Permission API permission missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94151"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-15801",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-22",
      "title": "Cri-o: cri-o: insufficient validation during container checkpoint restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15801"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-94148",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "ScadaBR",
      "cwe": "CWE-200",
      "title": "ScadaBR Export Project Endpoint export_project.htm EmportDwr.createExportJSON information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94148"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-94185",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.2224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nvm-sh",
      "product": "nvm",
      "cwe": "CWE-22",
      "title": "nvm alias resolution follows `..` and discloses files outside $NVM_DIR/alias",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94185"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-47321",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA",
      "cwe": "CWE-409",
      "title": "Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47321"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-94110",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "QCMS",
      "cwe": "CWE-74",
      "title": "QCMS Content Detail Controllers.php self_Tmp sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94110"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-94143",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "drogonframework",
      "product": "drogon",
      "cwe": "CWE-74",
      "title": "drogonframework drogon ORM Mapper Mapper.h orderBy sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94143"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-94144",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "drogonframework",
      "product": "drogon",
      "cwe": "CWE-74",
      "title": "drogonframework drogon ORM Criteria.cc makeCriteria sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94144"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-94102",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "WuzhiCMS",
      "cwe": "CWE-601",
      "title": "WuzhiCMS Login index.php redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94102"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-94103",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00239,
      "epss_percentile": 0.15185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "RooCMS",
      "cwe": "CWE-74",
      "title": "RooCMS Frontend Rendering site_pagePHP.php eval code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94103"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-94213",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: authorization services policy evaluation endpoint leaks user identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94213"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-94149",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00221,
      "epss_percentile": 0.12937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "HRM OS",
      "cwe": "CWE-99",
      "title": "Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94149"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-94152",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "FBP Fulfillment by People",
      "cwe": "CWE-285",
      "title": "Omega Solution FBP Fulfillment by People User Profile API user authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94152"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-94218",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00202,
      "epss_percentile": 0.10473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94218"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-94150",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00202,
      "epss_percentile": 0.104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omega Solution",
      "product": "HRM OS",
      "cwe": "CWE-79",
      "title": "Omega Solution HRM OS SVG File Upload view cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94150"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-85010",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RestroPress",
      "cwe": "CWE-472",
      "title": "RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85010"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-94145",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xuxueli",
      "product": "xxl-job",
      "cwe": "CWE-79",
      "title": "xuxueli xxl-job Task Management JobInfoController.java cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94145"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-94215",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.0825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: cross-realm client read/write via request-level cache missing realm ownership check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94215"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-85113",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GiveWP",
      "cwe": "CWE-74",
      "title": "GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85113"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-90860",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canva",
      "product": "Canva",
      "cwe": "CWE-212",
      "title": "The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90860"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-86802",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00158,
      "epss_percentile": 0.05359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "To Do List Member",
      "cwe": "CWE-862",
      "title": "To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86802"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-82187",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00145,
      "epss_percentile": 0.04187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Web to Print Online Designer",
      "cwe": "CWE-434",
      "title": "WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82187"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-94217",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: uma scope merge across resource owners via resource name collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94217"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-94142",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BioStar",
      "product": "Temperature Monitor Utility",
      "cwe": "CWE-119",
      "title": "BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94142"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-94128",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BioStar",
      "product": "VIVID LED DJ",
      "cwe": "CWE-119",
      "title": "BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94128"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-94129",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.0248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BioStar",
      "product": "VALKYRIE AURORA",
      "cwe": "CWE-119",
      "title": "BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94129"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-94146",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.0248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BioStar",
      "product": "BIOS Update Utility",
      "cwe": "CWE-119",
      "title": "BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94146"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-92400",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payment Gateway for PayPal on WooCommerce",
      "cwe": "CWE-345",
      "title": "Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92400"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-94137",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hangzhou Shunwang Technology",
      "product": "shzh",
      "cwe": "CWE-404",
      "title": "Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94137"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-77521",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-78",
      "title": "MaxKB: Prompt-injectable agent can lead to command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77521"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-79920",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ajenti",
      "product": "ajenti",
      "cwe": "CWE-862",
      "title": "Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79920"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-85751",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mailu",
      "product": "Mailu",
      "cwe": "CWE-290",
      "title": "Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85751"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-94301",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA",
      "cwe": "CWE-502",
      "title": "Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94301"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-94571",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Octavia",
      "cwe": "CWE-94",
      "title": "In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw unencoded value directly into the HAProxy configuration generated on the amphora. An authenticated project member who owns a load balancer can therefore inject arbitrary HAProxy directives through a REDIRECT_TO_URL L7 policy. Only deployments using the Amphora provider are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94571"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-94572",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Octavia",
      "cwe": "CWE-94",
      "title": "In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployments using the Amphora provider are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94572"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-58491",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warp-tech",
      "product": "warpgate",
      "cwe": "CWE-79",
      "title": "Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58491"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-94424",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moore Threads",
      "product": "MTT S80 Driver Package",
      "cwe": "CWE-119",
      "title": "Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94424"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-94425",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moore Threads",
      "product": "MTT S80 Driver Package",
      "cwe": "CWE-266",
      "title": "Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94425"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-61674",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fluent",
      "product": "fluent-bit",
      "cwe": "CWE-121",
      "title": "Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61674"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-46649",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-307",
      "title": "Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46649"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-79916",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-78",
      "title": "MaxKB AWS Bedrock model credential injection leads to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79916"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-86473",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-613",
      "title": "Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86473"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-55563",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feast-dev",
      "product": "feast",
      "cwe": "CWE-863",
      "title": "Feast: `pull_request_target` integration tests run untrusted fork code with production cloud secrets; the `ok-to-test` label guard is bypassable via label persistence on `synchronize`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55563"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-88807",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X.org",
      "product": "libXrender",
      "cwe": "CWE-122",
      "title": "libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88807"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-53940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "conda",
      "product": "conda",
      "cwe": "CWE-22",
      "title": "Conda: Entry-point path traversal in noarch:python install (arbitrary file write) — canonical Python implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53940"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-55159",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci-app-adblock-fast",
      "cwe": "CWE-93",
      "title": "luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55159"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-55897",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-78",
      "title": "luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55897"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-62182",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubeedge",
      "product": "kubeedge",
      "cwe": "CWE-78",
      "title": "KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62182"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-62371",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubeedge",
      "product": "kubeedge",
      "cwe": "CWE-78",
      "title": "KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62371"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-63116",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deepstreamIO",
      "product": "deepstream.io",
      "cwe": "CWE-862",
      "title": "deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63116"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-82412",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntop",
      "product": "ntopng",
      "cwe": "CWE-78",
      "title": "ntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82412"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-84285",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "Tuleap Enterprise Edition",
      "cwe": "CWE-78",
      "title": "OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84285"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-84990",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntop",
      "product": "ntopng",
      "cwe": "CWE-200",
      "title": "ntopng: Missing Authorization on System Configuration Backup Download and Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84990"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-88409",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88409"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-92574",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Confidential Compute Attestation",
      "cwe": "CWE-250",
      "title": "Cri-o: cri-o checkpoint restore bypasses destination security context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92574"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-16651",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "temporalio/sqlparser",
      "cwe": "CWE-129",
      "title": "temporalio/sqlparser malformed MySQL version comments can cause a panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16651"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-61652",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kap-sh",
      "product": "zapros",
      "cwe": "CWE-770",
      "title": "Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61652"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-65651",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "temporalio/sqlparser",
      "cwe": "CWE-674",
      "title": "temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65651"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-65652",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "temporalio/tchannel-go",
      "cwe": "CWE-129",
      "title": "temporalio/tchannel-go malformed checksum type causes process termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65652"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-65653",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "temporalio/tchannel-go",
      "cwe": "CWE-129",
      "title": "temporalio/tchannel-go zero-chunk call fragment causes process termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65653"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-65654",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "temporalio/ringpop-go",
      "cwe": "CWE-770",
      "title": "temporalio/ringpop-go fails to enforce configured label limits on inbound membership gossip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65654"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-89139",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "Temporal Server",
      "cwe": "CWE-78",
      "title": "Temporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89139"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-94381",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-269",
      "title": "MISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via updateLoginTime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94381"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-94411",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-862",
      "title": "jshERP 3.6 Privilege Escalation via updateOneValueByKeyIdAndType",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94411"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-94412",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-862",
      "title": "jshERP through 3.6 Authorization Bypass via resetPwd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94412"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-94496",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-862",
      "title": "jshERP through 3.6 Privilege Escalation via Role Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94496"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-94497",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-639",
      "title": "jshERP through 3.6 Unauthorized Access via by-id Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94497"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-94501",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-862",
      "title": "jshERP through 3.6 Privilege Escalation via userBusiness CRUD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94501"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-94622",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-248",
      "title": "vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94622"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-94623",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-617",
      "title": "vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94623"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-94624",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-770",
      "title": "vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94624"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-94626",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-789",
      "title": "vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94626"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-94627",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-401",
      "title": "vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94627"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2025-71421",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvdesk",
      "product": "core-framework",
      "cwe": "CWE-269",
      "title": "UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71421"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-94383",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted File Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94383"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-94403",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ColorFul",
      "product": "iGameCenter",
      "cwe": "CWE-822",
      "title": "ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94403"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-49811",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Command | Monitor (DCM)",
      "cwe": "CWE-732",
      "title": "Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49811"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-55071",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SepineTam",
      "product": "mcp-for-stata",
      "cwe": "CWE-94",
      "title": "MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55071"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-94374",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-472",
      "title": "MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparenting and Overwriting of Other Events' Reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94374"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-94401",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-73",
      "title": "MISP Arbitrary Local File Read and SSRF via MISP Export Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94401"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-94488",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Telegram",
      "product": "Telegram Desktop",
      "cwe": "CWE-79",
      "title": "Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94488"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-55074",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chofstede",
      "product": "ansible_jailexec",
      "cwe": "CWE-59",
      "title": "Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55074"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-48826",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysadminsmedia",
      "product": "homebox",
      "cwe": "CWE-269",
      "title": "HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Tenant Header Switching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48826"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-48975",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysadminsmedia",
      "product": "homebox",
      "cwe": "CWE-639",
      "title": "HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampering and Destruction of Any User's Maintenance History in Homebox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48975"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-48976",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysadminsmedia",
      "product": "homebox",
      "cwe": "CWE-522",
      "title": "HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and Allows Webhook Hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48976"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-58269",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sync-in",
      "product": "server",
      "cwe": "CWE-288",
      "title": "Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58269"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-61628",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lucasdillmann",
      "product": "nginx-ignition",
      "cwe": "CWE-362",
      "title": "nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61628"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-62369",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubeedge",
      "product": "kubeedge",
      "cwe": "CWE-22",
      "title": "KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62369"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-77560",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyauthapp",
      "product": "tinyauth",
      "cwe": "CWE-178",
      "title": "Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77560"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-80110",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 9",
      "cwe": "CWE-863",
      "title": "Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw profile creation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80110"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-83621",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntop",
      "product": "ntopng",
      "cwe": "CWE-862",
      "title": "ntopng: Missing Authorization Check in REST API Allows Non-Admin Users to Tamper Threat Intelligence Blacklist URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83621"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-94184",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94184"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-65980",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chartbrew",
      "product": "chartbrew",
      "cwe": "CWE-89",
      "title": "Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variable Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65980"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-17052",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allows arbitrary supervisor-memory write from userspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17052"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-49810",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Command Powershell Provider (DCPP)",
      "cwe": "CWE-532",
      "title": "Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49810"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-55567",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bleachbit",
      "product": "bleachbit",
      "cwe": "CWE-367",
      "title": "BleachBit: Exploit File Delete to Escalate Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55567"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-81469",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Inventory Collector Client",
      "cwe": "CWE-428",
      "title": "Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81469"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-55105",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-79",
      "title": "Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55105"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-63330",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warp-tech",
      "product": "warpgate",
      "cwe": "CWE-285",
      "title": "Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authenticated User to Eavesdrop on Terminal Sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63330"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-76898",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgraph",
      "product": "drawio",
      "cwe": "CWE-918",
      "title": "draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76898"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-59814",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-79",
      "title": "Joplin: Stored XSS via inline-served note attachment on published shares",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59814"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-52741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-80",
      "title": "GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52741"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-61629",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lucasdillmann",
      "product": "nginx-ignition",
      "cwe": "CWE-770",
      "title": "nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61629"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-71543",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbao",
      "product": "openbao",
      "cwe": "CWE-863",
      "title": "OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71543"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-73512",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-416",
      "title": "Envoy: use-after-free in QUIC on internal redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73512"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-73513",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-20",
      "title": "Envoy: oghttp2 upstream trailers incorrect handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73513"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-73547",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-20",
      "title": "Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73547"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-73548",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-444",
      "title": "Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73548"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-73550",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-401",
      "title": "Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73550"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-73552",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-20",
      "title": "Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73552"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-73553",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-436",
      "title": "Envoy: RBAC Authorization Bypass via Path Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73553"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-88406",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88406"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-88407",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88407"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-88411",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88411"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-88806",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libX11",
      "cwe": "CWE-122",
      "title": "libX11 XkbGetMap Reply Heap-based Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88806"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-91863",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-674",
      "title": "Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91863"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-91864",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-770",
      "title": "Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91864"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-91865",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-770",
      "title": "Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91865"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-91866",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-770",
      "title": "Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91866"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-94449",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Exploit Intelligence",
      "cwe": "CWE-400",
      "title": "Quarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory leak in @applyguard leads to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94449"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-55210",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-290",
      "title": "Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55210"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-73546",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-79",
      "title": "Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73546"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-75939",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-347",
      "title": "Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75939"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-77523",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-639",
      "title": "MaxKB: Cross-workspace model parameter form write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77523"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-93340",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladys Assistant",
      "product": "Gladys Assistant",
      "cwe": "CWE-640",
      "title": "Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93340"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-94540",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MrPear",
      "product": "DesktopSMS",
      "cwe": "CWE-306",
      "title": "DesktopSMS 1.11.0 Unauthorized Access via Local Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94540"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-36467",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36467"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-87858",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "Temporal Server",
      "cwe": "CWE-807",
      "title": "Temporal Server completion callback source header can direct attacker-chosen requests to the internal frontend with administrator authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87858"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-16652",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "Temporal Server",
      "cwe": "CWE-606",
      "title": "Temporal Server Schedule exclusion search can cause excessive CPU consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16652"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-49450",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-345",
      "title": "Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49450"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-61647",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roomi-fields",
      "product": "notebooklm-mcp",
      "cwe": "CWE-22",
      "title": "@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61647"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-61687",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hatchet-dev",
      "product": "hatchet",
      "cwe": "CWE-287",
      "title": "hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61687"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-88410",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88410"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-94368",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Openshift Data Foundation 4",
      "cwe": "CWE-347",
      "title": "Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-copy-source header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94368"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-94404",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-352",
      "title": "MISP CSRF vulnerability allows unauthorized attribute modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94404"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-94413",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-200",
      "title": "jshERP through 3.6 Password Hash Disclosure via /user/info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94413"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-94495",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-862",
      "title": "jshERP through 3.6 Missing Authorization via systemConfig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94495"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-94532",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-639",
      "title": "lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94532"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-94533",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-639",
      "title": "lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94533"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-94534",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-639",
      "title": "lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94534"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-94535",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-639",
      "title": "lamp-cloud through 5.10.0 Unauthorized Notification Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94535"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-49453",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-20",
      "title": "Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49453"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-52835",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-22",
      "title": "Tautulli: Path traversal / arbitrary file write via unsanitized upload filename in import_config and import_database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52835"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-68919",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-80",
      "title": "GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68919"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-61541",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kap-sh",
      "product": "zapros",
      "cwe": "CWE-770",
      "title": "Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61541"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-77582",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyauthapp",
      "product": "tinyauth",
      "cwe": "CWE-208",
      "title": "Tinyauth: User enumeration attack by timing oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77582"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-94379",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94379"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-94625",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-772",
      "title": "vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94625"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-58271",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sync-in",
      "product": "server",
      "cwe": "CWE-307",
      "title": "@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58271"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-63334",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgraph",
      "product": "drawio",
      "cwe": "CWE-367",
      "title": "draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63334"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-55179",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-639",
      "title": "Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55179"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-58270",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sync-in",
      "product": "server",
      "cwe": "CWE-1333",
      "title": "Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58270"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-61744",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inventree",
      "product": "InvenTree",
      "cwe": "CWE-639",
      "title": "InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view role",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61744"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-61749",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inventree",
      "product": "InvenTree",
      "cwe": "CWE-200",
      "title": "InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61749"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-61851",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chartbrew",
      "product": "chartbrew",
      "cwe": "CWE-184",
      "title": "Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61851"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-62247",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supabase",
      "product": "realtime",
      "cwe": "CWE-863",
      "title": "Supabase Realtime: Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62247"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-62370",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubeedge",
      "product": "kubeedge",
      "cwe": "CWE-789",
      "title": "KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62370"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-77165",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Server",
      "cwe": "CWE-284",
      "title": "File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77165"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-79917",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-285",
      "title": "MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79917"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-88408",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88408"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-94393",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-284",
      "title": "MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94393"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-61743",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chartbrew",
      "product": "chartbrew",
      "cwe": "CWE-350",
      "title": "Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61743"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-63342",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hatchet-dev",
      "product": "hatchet",
      "cwe": "CWE-863",
      "title": "Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63342"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-69190",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Graylog2",
      "product": "graylog2-server",
      "cwe": "CWE-639",
      "title": "Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69190"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-79918",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-693",
      "title": "MaxKB: Sandbox escape via unhooked fexecve",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79918"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-79919",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-693",
      "title": "MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79919"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-94277",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Galaxy Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94277"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-94372",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via Unescaped Galaxy Cluster Tag Names in MISP Default Theme Galaxies Index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94372"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-94373",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP DOM-based Cross-Site Scripting via innerHTML in Contextual Menu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94373"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-94394",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-862",
      "title": "MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object References",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94394"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-59168",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TomWright",
      "product": "dasel",
      "cwe": "CWE-674",
      "title": "Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59168"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-62866",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TomWright",
      "product": "dasel",
      "cwe": "CWE-129",
      "title": "Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62866"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-36468",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as \"><script>alert(1)</script>).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36468"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-58504",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgraph",
      "product": "drawio",
      "cwe": "CWE-79",
      "title": "draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass of CVE-2026-46642",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58504"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-17051",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound doorbell length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17051"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-55473",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysadminsmedia",
      "product": "homebox",
      "cwe": "CWE-918",
      "title": "HomeBox: Notifier SSRF guard misses NAT64 prefixes (64:ff9b::/96, 64:ff9b:1::/48) — generic:// URL reaches cloud metadata on NAT64 egress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55473"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-91167",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warp-tech",
      "product": "warpgate",
      "cwe": "CWE-862",
      "title": "Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allows any admin to bypass the `AccessRolesAssign` permission boundary",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91167"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-48521",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-476",
      "title": "Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48521"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-50572",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-416",
      "title": "Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50572"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-61852",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chartbrew",
      "product": "chartbrew",
      "cwe": "CWE-89",
      "title": "Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61852"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-62987",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fabiolb",
      "product": "fabio",
      "cwe": "CWE-290",
      "title": "Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62987"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-17050",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-415",
      "title": "Double free of the USB host configuration descriptor when device enumeration fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17050"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-61612",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ondata",
      "product": "ckan-mcp-server",
      "cwe": "CWE-918",
      "title": "@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61612"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-91166",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warp-tech",
      "product": "warpgate",
      "cwe": "CWE-297",
      "title": "Warpgate: Web SSH stores a jump host's key against the target's address, so it validates as the target",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91166"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-82163",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Command | Intel vPro Out of Band",
      "cwe": "CWE-276",
      "title": "Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82163"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-82165",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Command | Integration Suite for System Center",
      "cwe": "CWE-276",
      "title": "Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82165"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-93433",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93433"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-48974",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysadminsmedia",
      "product": "homebox",
      "cwe": "CWE-841",
      "title": "HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48974"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-54915",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-601",
      "title": "Tautulli: Open redirect via whitespace bypass in /auth/redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54915"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-59830",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Stored XSS via unescaped actor name in post actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59830"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-77516",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-639",
      "title": "MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77516"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-77517",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-639",
      "title": "MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77517"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-77519",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-613",
      "title": "MaxKB: Expired application API keys remain usable on `/chat/api/mcp`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77519"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-77520",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-862",
      "title": "MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77520"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2025-71420",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvdesk",
      "product": "core-framework",
      "cwe": "CWE-639",
      "title": "UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71420"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-15890",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-323",
      "title": "AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15890"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-17054",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17054"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-52740",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-863",
      "title": "GoCD is vulnerable to pipeline template view API authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52740"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-54584",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MidnightBSD",
      "product": "mport",
      "cwe": "CWE-73",
      "title": "mport trusts environment-controlled temporary directories in privileged metadata extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54584"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-58272",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sync-in",
      "product": "server",
      "cwe": "CWE-208",
      "title": "Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58272"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-61746",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inventree",
      "product": "InvenTree",
      "cwe": "CWE-200",
      "title": "InvenTree: Plugin-settings GET endpoints are readable without authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61746"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-73511",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-289",
      "title": "Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache Tomcat)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73511"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-73549",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-754",
      "title": "Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73549"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-73551",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-647",
      "title": "Envoy: Path normalization does not handle dot and dotdot segments with parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73551"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-77021",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-409",
      "title": "Missing decompression size limit in agent receiver allows memory exhaustion via push agent data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77021"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-77561",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyauthapp",
      "product": "tinyauth",
      "cwe": "CWE-307",
      "title": "Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77561"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-88412",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88412"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-94414",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-862",
      "title": "jshERP through 3.6 Missing Authorization via updateBtnStr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94414"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-94489",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OctoPrint",
      "cwe": "CWE-22",
      "title": "OctoPrint File Download API files.py _validate path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94489"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-94494",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jishenghua",
      "product": "jshERP",
      "cwe": "CWE-639",
      "title": "jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94494"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-94536",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-639",
      "title": "lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94536"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-36472",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36472"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2025-71419",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvdesk",
      "product": "core-framework",
      "cwe": "CWE-79",
      "title": "UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71419"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-45381",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-79",
      "title": "Tautulli: Reflected XSS in `/search` endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45381"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-52742",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-863",
      "title": "GoCD is vulnerable to historical server configuration API authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52742"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-91921",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1millionbot",
      "product": "AI Chatbot Platform (SaaS) de 1millionbot.",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91921"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-93339",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metaphor Creations",
      "product": "Ditty",
      "cwe": "CWE-79",
      "title": "Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93339"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-94387",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aureuserp",
      "product": "aureuserp",
      "cwe": "CWE-79",
      "title": "Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94387"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-77518",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-862",
      "title": "MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77518"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-55625",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-639",
      "title": "GoCD is vulnerable to authorization bypass via material connection test APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55625"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-63329",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warp-tech",
      "product": "warpgate",
      "cwe": "CWE-116",
      "title": "Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Spoofing to WebSocket Backend Targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63329"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-49995",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-79",
      "title": "Tautulli: Stored Cross-Site Scripting (XSS) in the newsletter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49995"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-46650",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-79",
      "title": "Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46650"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-94588",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Proxmox",
      "product": "pmg-api",
      "cwe": "CWE-88",
      "title": "In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94588"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-52743",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-639",
      "title": "GoCD before 26.1.0 is vulnerable to authorization bypass via job status API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52743"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-59815",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-863",
      "title": "Joplin: Pending share recipients can write items into shared folders before accepting invitations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59815"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-59816",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-22",
      "title": "Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59816"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-61745",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inventree",
      "product": "InvenTree",
      "cwe": "CWE-862",
      "title": "InvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equipment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61745"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-61747",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inventree",
      "product": "InvenTree",
      "cwe": "CWE-639",
      "title": "InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column mappings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61747"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-61748",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inventree",
      "product": "InvenTree",
      "cwe": "CWE-639",
      "title": "InvenTree: Report/Label print endpoints ignore per-model permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61748"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-75158",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75158"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-77522",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-918",
      "title": "MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77522"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-88978",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hatchet-dev",
      "product": "hatchet",
      "cwe": "CWE-639",
      "title": "Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88978"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-91164",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warp-tech",
      "product": "warpgate",
      "cwe": "CWE-284",
      "title": "Warpgate: API tokens bypass the user's allowed_ip_ranges restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91164"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-91867",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-400",
      "title": "Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91867"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-61630",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lucasdillmann",
      "product": "nginx-ignition",
      "cwe": "CWE-287",
      "title": "nginx ignition has TOTP Reuse During Validity Window",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61630"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-63373",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgraph",
      "product": "drawio",
      "cwe": "CWE-352",
      "title": "draw.io: OAuth CSRF via missing state validation on self-hosted deployments allows session token injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63373"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-77525",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-862",
      "title": "MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77525"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-82355",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-384",
      "title": "Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82355"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-61681",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hatchet-dev",
      "product": "hatchet",
      "cwe": "CWE-918",
      "title": "Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61681"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-92382",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92382"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-55060",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-863",
      "title": "GoCD is vulnerable to authorization bypass via support process list API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55060"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-63416",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgraph",
      "product": "drawio",
      "cwe": "CWE-22",
      "title": "draw.io: Path traversal in ExportProxyServlet allows access to arbitrary backend endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63416"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-85219",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkst Applied Research",
      "product": "OpenCanary",
      "cwe": "CWE-770",
      "title": "Denial-of-Service in the OpenCanary Redis service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85219"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-85220",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkst Applied Research",
      "product": "Canary",
      "cwe": "CWE-770",
      "title": "Denial-of-Service in the Thinkst Canary Redis service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85220"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-84298",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hatchet-dev",
      "product": "hatchet",
      "cwe": "CWE-639",
      "title": "Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84298"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-49449",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laurent22",
      "product": "joplin",
      "cwe": "CWE-200",
      "title": "Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49449"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-77166",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nextcloud",
      "product": "Collectives",
      "cwe": "CWE-840",
      "title": "The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77166"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-91165",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warp-tech",
      "product": "warpgate",
      "cwe": "CWE-79",
      "title": "Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91165"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-55870",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-200",
      "title": "GoCD is vulnerable to credential exposure when admins insecurely configure material URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55870"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-94382",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "henrygd",
      "product": "beszel",
      "cwe": "CWE-639",
      "title": "Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94382"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-94214",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ST Engineering iDirect",
      "product": "Evolution",
      "cwe": "CWE-601",
      "title": "ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94214"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-94216",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ST Engineering iDirect",
      "product": "Evolution",
      "cwe": "CWE-601",
      "title": "ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header webserver authorize redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94216"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-94210",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hyve5",
      "product": "Leantime",
      "cwe": "CWE-79",
      "title": "Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94210"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-94426",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xuxueli",
      "product": "xxl-job",
      "cwe": "CWE-79",
      "title": "xuxueli xxl-job insert cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94426"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-94211",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hyve5",
      "product": "Leantime",
      "cwe": "CWE-79",
      "title": "Hyve5 Leantime Project Dashboard show.blade.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94211"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-92612",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse iceoryx™",
      "cwe": "CWE-749",
      "title": "In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92612"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-36469",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's \"Upload by URL\" functionality).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36469"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-36470",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the \"Referer\" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36470"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-36471",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36471"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-67827",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67827"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-78806",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78806"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-78847",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78847"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-79079",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79079"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-79316",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79316"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-79317",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the database or any session version. When an administrator changes the username or password, previously issued session cookies are not revoked, so an attacker who holds a pre-change admin cookie can continue accessing and operating the management interface after the credentials have been rotated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79317"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-79318",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79318"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-79319",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Stencil core 4.43.5 is vulnerable to Incorrect Access Control.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79319"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-79320",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the textContent property of such a component's host element causes the value to be parsed as HTML instead of being inserted as text. If an application writes attacker-controlled data to these host elements, the data can be interpreted as markup and script can execute in the context of the application's origin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79320"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-88402",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88402"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-88403",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88403"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-88404",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88404"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-88405",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88405"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-88467",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88467"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-88738",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88738"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-88745",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88745"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-88746",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88746"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-88756",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88756"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-93012",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Email-Sender",
      "cwe": "CWE-78",
      "title": "Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93012"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-7273",
      "detail": "ADDED TO KEV — CVE-2026-7273 (Zyxel GS1900-48HPv2 firmware). Remediation due September 24, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-43000",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-43000 (Apple macOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-54399",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-54399 (Hongjing e-HR). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-58385",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-58385 (Yonyou U8 CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-5914",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26731",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26731. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70640",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70640 (ggml-org llama.cpp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85046",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85046 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86861",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86861 (pgadmin.org pgAdmin 4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86862",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86862 (pgadmin.org pgAdmin 4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90499",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90499 (lenve vhr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90504",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90504 (vvbbnn00 WARP-Clash-API). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90828 (GNU Binutils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92457",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92457 (guchengwuyue yshop-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92462",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92462 (guchengwuyue yshop-crm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92467",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92467 (zlt2000 microservices-platform). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92770",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92770 (goharbor harbor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92775",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92775 (requarks Wiki.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92796",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92796 (manticoresoftware Manticore Search). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92811",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92811 (browserless). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92816",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92816 (Comfy-Org ComfyUI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92927",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92927 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93309",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93309 (O-RAN-SC SMO OAM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93314",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93314 (Freedesktop Poppler). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93454",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93740 (Totolink A3002MU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93742",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93742 (Totolink A3002MU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93955",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93955 (grimmory-tools grimmory). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93956",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93956 (olivier-ls PHP-FTS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93958",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93958 (D-Link R95). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93963",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93963 (itsourcecode Leave Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93973",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93973 (SourceCodester Online Reviewer Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93975",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93975 (code-projects Assessment Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93976",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93976 (code-projects Assessment Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93978",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93978 (code-projects Internship Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93980",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93980 (code-projects Internship Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93988",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93988 (webkul qloapps). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93997 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94028",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94028 (mealie-recipes Mealie). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94031",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94031 (0-Gaurav-0 nexus-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94033 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94034",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94034 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94036",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94036 (D-Link DIR-X1860). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94038",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94038 (NonceGeek dim-sum-app). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94039",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94039 (vas3k TaxHacker). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94041 (AdithyaYelloju Restaurant-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94044 (03-lovepreetSingh MCP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94046",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94046 (0215AndrewFeng ACE-MCP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94048",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94048 (CodeAstro QR Code Attendance Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94049",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94049 (06ketan slideshot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94051",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94051 (0717376 cowork_bench). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94091",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94091 (piskvorky gensim). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-35768",
      "detail": "RESCORED — CVE-2024-35768 (Live Composer Team Page Builder: Live Composer). CVSS 5.9 → 4.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-40766",
      "detail": "RESCORED — CVE-2024-40766 (SonicWall SonicOS). CVSS 9.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39682",
      "detail": "RESCORED — CVE-2025-39682 (Linux). CVSS 7.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-43936",
      "detail": "RESCORED — CVE-2025-43936 (Dell ObjectScale). CVSS 8.1 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-26731",
      "detail": "RESCORED — CVE-2026-26731. CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-28367",
      "detail": "RESCORED — CVE-2026-28367 (Red Hat JBoss Enterprise Application Platform 8.1.7.GA). CVSS 8.7 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-28368",
      "detail": "RESCORED — CVE-2026-28368 (Red Hat JBoss Enterprise Application Platform 8.1.7.GA). CVSS 8.7 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69597",
      "detail": "RESCORED — CVE-2026-69597 (Microsoft Windows 11 version 23H2). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69602",
      "detail": "RESCORED — CVE-2026-69602 (Microsoft Windows 10 Version 1809). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69619",
      "detail": "RESCORED — CVE-2026-69619 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69625",
      "detail": "RESCORED — CVE-2026-69625 (Microsoft Windows 10 Version 1809). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70416",
      "detail": "RESCORED — CVE-2026-70416 (Dell ObjectScale). CVSS 10 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71179",
      "detail": "RESCORED — CVE-2026-71179 (Dell Update Package Framework). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71180",
      "detail": "RESCORED — CVE-2026-71180 (Dell Update Package Framework). CVSS 8.2 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71181",
      "detail": "RESCORED — CVE-2026-71181 (Dell Update Package Framework). CVSS 3 → 6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71182",
      "detail": "RESCORED — CVE-2026-71182 (Dell Update Package Framework). CVSS 3 → 6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72947",
      "detail": "RESCORED — CVE-2026-72947 (Microsoft Windows 10 Version 1607). CVSS 6.4 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72948",
      "detail": "RESCORED — CVE-2026-72948 (Microsoft Windows 10 Version 1607). CVSS 6.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72950",
      "detail": "RESCORED — CVE-2026-72950 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81235",
      "detail": "RESCORED — CVE-2026-81235 (Dell Wyse Management Suite). CVSS 8 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81236",
      "detail": "RESCORED — CVE-2026-81236 (Dell Wyse Management Suite). CVSS 8.6 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81238",
      "detail": "RESCORED — CVE-2026-81238 (Dell Wyse Management Suite). CVSS 7.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81239",
      "detail": "RESCORED — CVE-2026-81239 (Dell Wyse Management Suite). CVSS 8.6 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81240",
      "detail": "RESCORED — CVE-2026-81240 (Dell Wyse Management Suite). CVSS 8.6 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81627",
      "detail": "RESCORED — CVE-2026-81627 (Red Hat Enterprise Linux 10). CVSS 6.7 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-86358",
      "detail": "RESCORED — CVE-2026-86358 (Dell Update Package Framework). CVSS 6.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94095",
      "detail": "RESCORED — CVE-2026-94095 (Netcore NBR200V2). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94096",
      "detail": "RESCORED — CVE-2026-94096 (Netcore NBR200V2). CVSS 9.4 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94097",
      "detail": "RESCORED — CVE-2026-94097 (Netcore NBR200V2). CVSS 10 → 9.3 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-68914",
      "detail": "REJECTED — CVE-2026-68914 (mojolicious mojo). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-77568",
      "detail": "REJECTED — CVE-2026-77568 (mojolicious mojo). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-80219",
      "detail": "REJECTED — CVE-2026-80219 (Red Hat build of Apache Camel - HawtIO 4). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-43961",
      "detail": "PATCH SHIPPED — CVE-2026-43961 (vim). Fixed in Red Hat Hardened Images 9.2.967-1.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-65492",
      "detail": "PATCH SHIPPED — CVE-2026-65492 (weDevs Dokan Pro). Fixed in Dokan Pro 5.0.7."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-66457",
      "detail": "PATCH SHIPPED — CVE-2026-66457 (Pixelite Events Manager). Fixed in Events Manager 7.4.3."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-6862",
      "detail": "PATCH SHIPPED — CVE-2026-6862 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 39-13.1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-71577",
      "detail": "PATCH SHIPPED — CVE-2026-71577 (Red Hat Multicluster Global Hub 1.4.9). Fixed in Multicluster Global Hub 1.4.9 1788355417."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-76781",
      "detail": "PATCH SHIPPED — CVE-2026-76781 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.15.3-0.1.3.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-78002",
      "detail": "PATCH SHIPPED — CVE-2026-78002 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:8.2510.0-5.el10_2.2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-78376",
      "detail": "PATCH SHIPPED — CVE-2026-78376 (WebKit). Fixed in Red Hat Enterprise Linux 9 0:2.54.0-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-83596",
      "detail": "PATCH SHIPPED — CVE-2026-83596 (WebKit). Fixed in Red Hat Enterprise Linux 9 0:2.54.0-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-85013",
      "detail": "PATCH SHIPPED — CVE-2026-85013 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 5.6.2-1.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-87876",
      "detail": "PATCH SHIPPED — CVE-2026-87876 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.4.19-4.2.hum1."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-92925",
      "detail": "PATCH SHIPPED — CVE-2026-92925 (Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions). Fixed in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 9040020260917140622.9."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-31710",
      "detail": "ENRICHED — CVE-2026-31710 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-92126",
      "detail": "ENRICHED — CVE-2026-92126 (Jenkins Project Jenkins Script Security Plugin). Received CVSS 8.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
