{
  "day": "2026-09-22",
  "boundary": "UTC calendar day",
  "published_count": 455,
  "by_severity": {
    "CRITICAL": 81,
    "HIGH": 170,
    "MEDIUM": 162,
    "LOW": 22
  },
  "kev_count": 3,
  "exploit_reference_count": 2,
  "awaiting_enrichment_count": 20,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-93952",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.36318,
      "kev": true,
      "kev_due_at": "2026-09-25",
      "vendor": "Arista Networks",
      "product": "VeloCloud Orchestrator (VCO) On-Prem",
      "cwe": "CWE-20",
      "title": "Security Advisory 0183",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93952"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-93616",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-09-25",
      "vendor": "checkpoint",
      "product": "Quantum Security Management",
      "cwe": "CWE-22",
      "title": "Directory Traversal and File upload allows execution of arbitrary script on the Management Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93616"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-94127",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-09-25",
      "vendor": "F5",
      "product": "BIG-IP",
      "cwe": "CWE-122",
      "title": "BIG-IP APM OAuth vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94127"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-94490",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.02097,
      "epss_percentile": 0.80862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OctoPrint",
      "cwe": "CWE-77",
      "title": "OctoPrint Command API system.py executeSystemCommand os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94490"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-15095",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01174,
      "epss_percentile": 0.66135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wahid0003",
      "product": "Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels",
      "cwe": "CWE-22",
      "title": "Product Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15095"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-94493",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0073,
      "epss_percentile": 0.52799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gigatech",
      "product": "PDV5701",
      "cwe": "CWE-287",
      "title": "Gigatech PDV5701 WebSocket Service index.html missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94493"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-92969",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0065,
      "epss_percentile": 0.49763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "realmag777",
      "product": "HUSKY – Products Filter for WooCommerce Professional",
      "cwe": "CWE-98",
      "title": "HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92969"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9231",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00578,
      "epss_percentile": 0.46313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wptravelengine",
      "product": "WP Travel Engine – Tour Booking Plugin – Tour Operator Software",
      "cwe": "CWE-98",
      "title": "WP Travel Engine <= 6.8.0 - Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9231"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2025-1281",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00566,
      "epss_percentile": 0.45739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SeaTheme",
      "product": "BM Content Builder",
      "cwe": "CWE-22",
      "title": "BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1281"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2025-1280",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00533,
      "epss_percentile": 0.43934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SeaTheme",
      "product": "BM Content Builder",
      "cwe": "CWE-22",
      "title": "BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1280"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-68956",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.4025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-770",
      "title": "SSH daemon allocates unbounded idle session channels, bypassing max_channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68956"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-95508",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.36294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95508"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-19658",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.34885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LiquidWeb",
      "product": "Give Tributes",
      "cwe": "CWE-502",
      "title": "Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19658"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-89422",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00368,
      "epss_percentile": 0.30701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-322",
      "title": "TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89422"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-92235",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.2988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxnor",
      "product": "WP Ultimate Review",
      "cwe": "CWE-94",
      "title": "WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92235"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-92438",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.28392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ninja Forms",
      "cwe": "CWE-79",
      "title": "Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92438"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-13355",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.28099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meta Box",
      "product": "Meta Box Frontend Submission",
      "cwe": "CWE-269",
      "title": "Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13355"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-12470",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "niteo",
      "product": "CMP – Coming Soon & Maintenance Plugin by NiteoThemes",
      "cwe": "CWE-269",
      "title": "CMP <= 4.1.17 - Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12470"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-6922",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wptb",
      "product": "WP Table Builder – Drag & Drop Table Builder",
      "cwe": "CWE-863",
      "title": "WP Table Builder <= 2.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6922"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-93556",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kompini",
      "product": "Tankuam Places",
      "cwe": "CWE-639",
      "title": "Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93556"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-91827",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ninja Forms",
      "cwe": "CWE-502",
      "title": "Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91827"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-89412",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozmoslabs",
      "product": "TranslatePress – Translate Multilingual sites with AI Translation",
      "cwe": "CWE-79",
      "title": "TranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89412"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-94504",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.22052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kstover",
      "product": "Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder",
      "cwe": "CWE-79",
      "title": "Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94504"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-93928",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "Taxi Booking Manager for WooCommerce",
      "cwe": "CWE-288",
      "title": "WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93928"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-85653",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ajay",
      "product": "Contextual Related Posts",
      "cwe": "CWE-79",
      "title": "Contextual Related Posts <= 4.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85653"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-94491",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yonyou",
      "product": "KSOA",
      "cwe": "CWE-74",
      "title": "Yonyou KSOA search_list.jsp sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94491"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-65634",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-407",
      "title": "Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65634"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-18439",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-639",
      "title": "Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18439"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-93778",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "WP Yelp Review Slider",
      "cwe": "CWE-79",
      "title": "WP Yelp Review Slider <= 9.2 - Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93778"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-91092",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-862",
      "title": "wpForo Forum <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Action / Forged comment_author_email Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91092"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-93836",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpclever",
      "product": "WPC Product Bundles for WooCommerce",
      "cwe": "CWE-79",
      "title": "WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93836"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2025-14484",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kamleshyadav",
      "product": "Image Buzz",
      "cwe": "CWE-862",
      "title": "Image Buzz <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary API Key Modification via 'pixabay_api' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14484"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2025-14486",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kamleshyadav",
      "product": "PixelPlay",
      "cwe": "CWE-862",
      "title": "PixelPlay <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14486"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2025-14487",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kamleshyadav",
      "product": "Handily",
      "cwe": "CWE-862",
      "title": "Handily <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Stripe Payment Settings Modification via 'stripe_publishbale_key' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14487"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-16778",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livecomposer",
      "product": "Live Composer – Free WordPress Website Builder",
      "cwe": "CWE-79",
      "title": "Live Composer <= 2.1.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16778"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-9004",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nofearinc",
      "product": "WP-CRM System – Manage Clients and Projects",
      "cwe": "CWE-200",
      "title": "WP-CRM System <= 3.4.6 - Authenticated (Contributor+) Exposure of Sensitive Information via 'contact_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9004"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-93655",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevelop",
      "product": "Booking Calendar",
      "cwe": "CWE-79",
      "title": "Booking Calendar <= 11.8.3 - Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93655"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-76974",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Fiori Launchpad",
      "cwe": "CWE-95",
      "title": "Information Disclosure vulnerability in SAP Fiori Launchpad",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76974"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-12995",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.1194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hiroaki-miyashita",
      "product": "Custom Field Template",
      "cwe": "CWE-639",
      "title": "Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File Deletion via 'file_field' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12995"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-4123",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rwelephant01",
      "product": "RW Elephant Rental Inventory",
      "cwe": "CWE-862",
      "title": "RW Elephant Rental Inventory <= 2.3.13 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'toggle_cache' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4123"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-7622",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codexpert",
      "product": "ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More",
      "cwe": "CWE-862",
      "title": "ThumbPress <= 6.2.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7622"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-18345",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpusermanager",
      "product": "WP User Manager – User Profile Builder & Membership",
      "cwe": "CWE-862",
      "title": "WP User Manager <= 2.9.18 - Missing Authorization to Authenticated (Subscriber+) Stripe Account Hijack via Stripe Connect Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18345"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-1645",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prasunsen",
      "product": "Hostel",
      "cwe": "CWE-79",
      "title": "Hostel <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_currency' Parameter and Localization file URL Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1645"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-88788",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Text Styler",
      "cwe": "CWE-79",
      "title": "Text Styler <= 1.1.1 - Contributor+ Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88788"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-94492",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yonyou",
      "product": "U8cloud",
      "cwe": "CWE-74",
      "title": "Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94492"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-93711",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.0866,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Dancer2",
      "cwe": "CWE-113",
      "title": "Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93711"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-93712",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08497,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Dancer2",
      "cwe": "CWE-22",
      "title": "Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93712"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-93709",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00186,
      "epss_percentile": 0.08497,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Dancer2",
      "cwe": "CWE-41",
      "title": "Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93709"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-93710",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06912,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Dancer2",
      "cwe": "CWE-460",
      "title": "Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93710"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2016-15059",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00171,
      "epss_percentile": 0.06797,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-122",
      "title": "Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-15059"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-87082",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05625,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-835",
      "title": "Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87082"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-74765",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05252,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-125",
      "title": "Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74765"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-74766",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05206,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-416",
      "title": "Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74766"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-87079",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05042,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-407",
      "title": "Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87079"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-87081",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05043,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-407",
      "title": "Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87081"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-87078",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00154,
      "epss_percentile": 0.04983,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-401",
      "title": "Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87078"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-87080",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00148,
      "epss_percentile": 0.04415,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-IDN-Encode",
      "cwe": "CWE-1286",
      "title": "Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87080"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-95503",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-347",
      "title": "Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95503"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-7866",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7866"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-73369",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-94",
      "title": "Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73369"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-75699",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-94",
      "title": "Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75699"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-75703",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-94",
      "title": "Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75703"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-75721",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-94",
      "title": "Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75721"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-75723",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75723"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-75745",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "AEM 6.5 Forms JEE",
      "cwe": "CWE-863",
      "title": "Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75745"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-77244",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-287",
      "title": "[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77244"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-80155",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-22",
      "title": "Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80155"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-84412",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-94",
      "title": "Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84412"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-89275",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-94",
      "title": "Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89275"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-16346",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-285",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16346"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-18169",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-22",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18169"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-57149",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plone",
      "product": "plone.app.portlets",
      "cwe": "CWE-95",
      "title": "plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57149"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-75682",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-89",
      "title": "Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75682"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-82008",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-20",
      "title": "Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82008"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-82010",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-89",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82010"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-82013",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-918",
      "title": "Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82013"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-83660",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-918",
      "title": "Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83660"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-89276",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-94",
      "title": "Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89276"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-12718",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Karel Electronic Industry and Trade Inc.",
      "product": "KarelIPS",
      "cwe": "CWE-89",
      "title": "SQLi in Karel Electronics' KarelIPS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12718"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-18162",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-94",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18162"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-18163",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-502",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18163"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-25254",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-285",
      "title": "Improper authorization in Qualcomm Software Center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25254"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-28324",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Observability Self-Hosted",
      "cwe": "CWE-345",
      "title": "SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28324"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-65113",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-798",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65113"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-74849",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine ADSelfService Plus",
      "cwe": "CWE-78",
      "title": "Remote code execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74849"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-76708",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": null,
      "title": "Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76708"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-76709",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": null,
      "title": "Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76709"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-79313",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-613",
      "title": "webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and used, allowing an attacker holding a previously valid session cookie to continue accessing protected resources after the configured idle timeout.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79313"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-93088",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-502",
      "title": "CVE-2026-93088",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93088"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-17472",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-269",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17472"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-82000",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "AEM 6.5 Forms JEE",
      "cwe": "CWE-918",
      "title": "Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82000"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-82443",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-918",
      "title": "Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82443"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-84388",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiPAM Chrome Extension",
      "cwe": "CWE-1021",
      "title": "A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84388"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-86059",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-200",
      "title": "Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86059"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-80143",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-78",
      "title": "Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80143"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-80144",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-78",
      "title": "Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80144"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-80145",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-78",
      "title": "Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80145"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-80146",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-121",
      "title": "Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80146"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-80147",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-121",
      "title": "Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80147"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-80151",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-78",
      "title": "Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80151"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-80152",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-78",
      "title": "Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80152"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-80156",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-22",
      "title": "Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80156"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-43641",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softaculous",
      "product": "Virtualizor",
      "cwe": "CWE-78",
      "title": "Softaculous Virtualizor OS Command Injection via Billing Module Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43641"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-47116",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LTSecurity",
      "product": "LTK3500SF",
      "cwe": "CWE-798",
      "title": "LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47116"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-63374",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agronholm",
      "product": "anyio",
      "cwe": "CWE-295",
      "title": "AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63374"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-75684",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-79",
      "title": "Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75684"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-75686",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-20",
      "title": "Adobe Connect | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75686"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-75689",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-79",
      "title": "Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75689"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-75697",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-79",
      "title": "Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75697"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-75698",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-79",
      "title": "Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75698"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-77621",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vectordotdev",
      "product": "vector",
      "cwe": "CWE-22",
      "title": "Vector: Arbitrary file write in the file sink via templated path (path traversal).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77621"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-77987",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-208",
      "title": "GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77987"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-87121",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lwIP",
      "product": "TCP/IP Stack MQTT",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87121"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-91130",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-80",
      "title": "Home Assistant: XSS in Statistics Graph Card",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91130"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-95675",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-LINK",
      "product": "DAP-1360",
      "cwe": "CWE-78",
      "title": "D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95675"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-18461",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-134",
      "title": "Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18461"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-43642",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softaculous",
      "product": "Virtualizor",
      "cwe": "CWE-502",
      "title": "Softaculous Virtualizor PHP Object Injection via Billing Module Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43642"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-17635",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-306",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17635"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-17645",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-269",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17645"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-19202",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "mcp-toolbox-sdk-python",
      "cwe": "CWE-524",
      "title": "Token Cache Reuse in mcp-toolbox-sdk-python",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19202"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-75728",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75728"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-77254",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-306",
      "title": "MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77254"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-81995",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "AEM 6.5 Forms JEE",
      "cwe": "CWE-20",
      "title": "Adobe Experience Manager Forms JEE | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81995"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-82009",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-89",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82009"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-82011",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-89",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82011"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-85734",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-307",
      "title": "LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85734"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-94456",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitroomHQ",
      "product": "postiz-app",
      "cwe": "CWE-330",
      "title": "Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organization API keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94456"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-95654",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David-Crty",
      "product": "Databasement",
      "cwe": "CWE-863",
      "title": "Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95654"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-80154",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-330",
      "title": "Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80154"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-13087",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13087"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-16468",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16468"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-16469",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16469"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-16672",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": null,
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16672"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-17102",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17102"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-17636",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-787",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17636"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-17637",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-502",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17637"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-17643",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-522",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17643"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-17644",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-798",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17644"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-17647",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-829",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17647"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-25255",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-749",
      "title": "Exposed function in Qualcomm Package Manager and Qualcomm Software Center.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25255"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-25264",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-427",
      "title": "Uncontrolled Search Path Element in Qualcomm Software Center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25264"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-25265",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-378",
      "title": "Creation of Temporary File with Insecure Permissions in Qualcomm Software Center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25265"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-28325",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Observability Self-Hosted",
      "cwe": "CWE-502",
      "title": "SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28325"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-65128",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-89",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65128"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-65179",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Speech",
      "cwe": "CWE-502",
      "title": "NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65179"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-70410",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Calcite Avatica",
      "cwe": "CWE-470",
      "title": "Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70410"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-77243",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-862",
      "title": "MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77243"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-77274",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-918",
      "title": "MCP Atlassian: SSRF Protection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77274"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-88419",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content validation and the file is written to the web-accessible uploadfile/ directory, from which the web server executes PHP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88419"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-18459",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-682",
      "title": "Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18459"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-43643",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softaculous",
      "product": "Virtualizor",
      "cwe": "CWE-862",
      "title": "Softaculous Virtualizor Authorization Bypass via Billing Module Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43643"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-67615",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apereo Foundation",
      "product": "openEQUELLA",
      "cwe": "CWE-184",
      "title": "openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Invoker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67615"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-77619",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vectordotdev",
      "product": "vector",
      "cwe": "CWE-130",
      "title": "Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory allocation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77619"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-77620",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vectordotdev",
      "product": "vector",
      "cwe": "CWE-409",
      "title": "Vector: Unauthenticated denial of service in the `logstash` source via nested compressed frames (stack exhaustion and decompression amplification).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77620"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-81999",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "AEM 6.5 Forms JEE",
      "cwe": "CWE-918",
      "title": "Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81999"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-90882",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "open-vsx.org",
      "cwe": "CWE-942",
      "title": "Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90882"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-91018",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lwIP",
      "product": "lwIP API",
      "cwe": "CWE-415",
      "title": "Double Free in lwIP (lightweight IP)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91018"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-93345",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-1284",
      "title": "MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93345"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-94450",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "s2n-quic",
      "cwe": "CWE-1284",
      "title": "Potential denial of service when configured to send Retry packets in s2n-quic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94450"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-95653",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "concretecms-community-store",
      "product": "community_store",
      "cwe": "CWE-340",
      "title": "Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95653"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-34689",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-22",
      "title": "Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34689"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-75791",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine ADSelfService Plus",
      "cwe": "CWE-306",
      "title": "Authentication bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75791"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-77248",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77248"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-77255",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77255"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-77262",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of CVE-2026-27825)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77262"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-85279",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-121",
      "title": "Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85279"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-95655",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aureuserp",
      "product": "aureuserp",
      "cwe": "CWE-639",
      "title": "Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95655"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-95814",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dani-garcia",
      "product": "vaultwarden",
      "cwe": "CWE-863",
      "title": "Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95814"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-17646",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-611",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17646"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-18095",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-787",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18095"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-82003",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-20",
      "title": "Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82003"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-83603",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-73",
      "title": "Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83603"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-18457",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18457"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-65114",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-306",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65114"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-77247",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-73",
      "title": "MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77247"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-77251",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-1276",
      "title": "MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77251"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-77256",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-732",
      "title": "MCP Atlassian: OAuth refresh-token backup file is world-readable under default Unix umask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77256"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-77257",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77257"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-77260",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77260"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-77267",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-918",
      "title": "mcp-atlassian has an incomplete SSRF remediation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77267"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-77271",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of CVE-2026-27825)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77271"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-18074",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-287",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18074"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-18131",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-79",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18131"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-65121",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-287",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65121"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-87119",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-294",
      "title": "mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87119"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-18137",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-89",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18137"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-75607",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blakeblackshear",
      "product": "frigate",
      "cwe": "CWE-862",
      "title": "Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75607"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-75744",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "AEM 6.5 Forms JEE",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75744"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-87902",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress",
      "product": "WordPress",
      "cwe": "CWE-98",
      "title": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87902"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-18154",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-321",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18154"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-65130",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-78",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65130"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-18066",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-918",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18066"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-24239",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Speech",
      "cwe": "CWE-502",
      "title": "NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24239"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-24267",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Speech",
      "cwe": "CWE-502",
      "title": "NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24267"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-65111",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Speech",
      "cwe": "CWE-77",
      "title": "NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65111"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-65178",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Speech",
      "cwe": "CWE-502",
      "title": "NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65178"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-75649",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-122",
      "title": "Bridge | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75649"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-75655",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-674",
      "title": "Bridge | Uncontrolled Recursion (CWE-674)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75655"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-75658",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-787",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75658"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-75663",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-787",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75663"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-75665",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-122",
      "title": "Bridge | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75665"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-75676",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-121",
      "title": "Bridge | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75676"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-77605",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-20",
      "title": "Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77605"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-79906",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Modeler",
      "cwe": "CWE-787",
      "title": "Substance3D - Modeler | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79906"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-81998",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Modeler",
      "cwe": "CWE-787",
      "title": "Substance3D - Modeler | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81998"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-83598",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-269",
      "title": "Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI Repair",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83598"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-83962",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Modeler",
      "cwe": "CWE-121",
      "title": "Substance3D - Modeler | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83962"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-83963",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Modeler",
      "cwe": "CWE-787",
      "title": "Substance3D - Modeler | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83963"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-86054",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-121",
      "title": "Notepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlong session path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86054"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-95831",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Crypt-SelfCertificate",
      "cwe": "CWE-506",
      "title": "Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95831"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-8849",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-416",
      "title": "Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8849"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-75608",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blakeblackshear",
      "product": "frigate",
      "cwe": "CWE-863",
      "title": "Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75608"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-77258",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77258"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-77259",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77259"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-80148",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-918",
      "title": "Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80148"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-80149",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-918",
      "title": "Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80149"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-80150",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LANTRONIX",
      "product": "SLC8000",
      "cwe": "CWE-918",
      "title": "Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80150"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-83803",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getsentry",
      "product": "sentry",
      "cwe": "CWE-502",
      "title": "Sentry: Unsafe pickle deserialization in Relocation Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83803"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-95619",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-190",
      "title": "Gcc: libstdc++ integer overflow in `new` operator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95619"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-95806",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-74",
      "title": "MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95806"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-18123",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-470",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18123"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-94117",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DevItems",
      "product": "HashBar – WordPress Notification Bar",
      "cwe": "CWE-89",
      "title": "WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94117"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-18134",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-319",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18134"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-19480",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19480"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-58268",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emiago",
      "product": "sipgo",
      "cwe": "CWE-789",
      "title": "SIPGO: DoS via unvalidated Content-Length in the stream parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58268"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-59991",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "psd-tools",
      "product": "psd-tools",
      "cwe": "CWE-789",
      "title": "psd-tools: Uncontrolled memory allocation in psd-tools composite/numpy via crafted PSD geometry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59991"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-61570",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joniles",
      "product": "mpxj",
      "cwe": "CWE-611",
      "title": "MPXJ: XXE Vulnerability in MerlinReader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61570"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-61685",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fecommunity",
      "product": "reactpress",
      "cwe": "CWE-89",
      "title": "ReactPress has SQL injection via dynamic column names in TypeORM query builders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61685"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-62985",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "azu",
      "product": "request-filtering-agent",
      "cwe": "CWE-248",
      "title": "request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62985"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-65118",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-295",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65118"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-75632",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75632"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-76710",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": null,
      "title": "Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76710"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-76711",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": null,
      "title": "Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76711"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-77242",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-367",
      "title": "MCP Atlassian: Incomplete fix for CVE-2026-27826: DNS rebinding bypasses SSRF validation (validated IP not pinned)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77242"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-77322",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emiago",
      "product": "sipgo",
      "cwe": "CWE-789",
      "title": "SIPGO: DoS via unvalidated WebSocket frame length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77322"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-77544",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-787",
      "title": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77544"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-77555",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-787",
      "title": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77555"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-77556",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-125",
      "title": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77556"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-77558",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-125",
      "title": "A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77558"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-83599",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-409",
      "title": "Netdata: WebSocket Decompression Bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83599"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-89407",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-core",
      "cwe": "CWE-400",
      "title": "jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() enables ReDoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89407"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-94640",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-400",
      "title": "Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94640"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-95861",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-674",
      "title": "A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95861"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-95862",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-787",
      "title": "A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95862"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-96269",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Emacs",
      "cwe": "CWE-829",
      "title": "GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96269"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-18152",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-347",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18152"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-18172",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-611",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18172"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-18176",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-319",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18176"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-77246",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77246"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-77912",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-79",
      "title": "Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77912"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-17618",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-862",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17618"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-18462",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-190",
      "title": "Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18462"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-19915",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP Support Assistant",
      "cwe": "CWE-269",
      "title": "HP Support Assistant - Local Escalation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19915"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-56681",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-807",
      "title": "9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56681"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-76712",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": "CWE-200",
      "title": "Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76712"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-85995",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-347",
      "title": "Notepad++: Authenticode verification bypass allows modified updater execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85995"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-63104",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usekaneo",
      "product": "kaneo",
      "cwe": "CWE-862",
      "title": "Kaneo 2.3.12 < 2.12.2 Missing Authorization via Bulk Task Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63104"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-76713",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": "CWE-269",
      "title": "Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76713"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-76714",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": "CWE-78",
      "title": "Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76714"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-94367",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenEye",
      "product": "Apex Network Video Recorder (NVR)",
      "cwe": "CWE-78",
      "title": "OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94367"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-95815",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw iOS",
      "cwe": "CWE-532",
      "title": "OpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL Logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95815"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-75743",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "AEM 6.5 Forms JEE",
      "cwe": "CWE-352",
      "title": "Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75743"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-76715",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": "CWE-300",
      "title": "Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76715"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-77253",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77253"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-77261",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-918",
      "title": "MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77261"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-77426",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unleash",
      "product": "unleash",
      "cwe": "CWE-639",
      "title": "Unleash: Missing await on permission check + cross-project IDOR in admin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77426"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-77633",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-362",
      "title": "Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77633"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-84395",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Premiere",
      "cwe": "CWE-918",
      "title": "Premiere Pro | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84395"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-85055",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-200",
      "title": "Twenty: Field-level read bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85055"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-85740",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-918",
      "title": "LightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85740"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-89420",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-1284",
      "title": "Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89420"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-93343",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebWizards",
      "product": "MarketKing",
      "cwe": "CWE-862",
      "title": "MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93343"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-93344",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebWizards",
      "product": "MarketKing",
      "cwe": "CWE-862",
      "title": "MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93344"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-94455",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitroomHQ",
      "product": "postiz-app",
      "cwe": "CWE-306",
      "title": "Unauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94455"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-94462",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spree",
      "product": "spree",
      "cwe": "CWE-639",
      "title": "Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94462"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-83597",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-269",
      "title": "Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83597"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-11388",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-415",
      "title": "Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11388"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-18460",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-193",
      "title": "Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18460"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-25262",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-123",
      "title": "Write-what-where Condition in Primary Bootloader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25262"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-63627",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wevm",
      "product": "mppx",
      "cwe": "CWE-20",
      "title": "mppx: Gas Draining with padding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63627"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-63628",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wevm",
      "product": "mppx",
      "cwe": "CWE-20",
      "title": "mppx: Gas Draining with access list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63628"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-95499",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JosephChuks",
      "product": "php-file-manager-with-code-editor",
      "cwe": "CWE-284",
      "title": "JosephChuks php-file-manager-with-code-editor filemanager.php move_uploaded_file unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95499"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-95658",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-352",
      "title": "MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-site execution of workflow modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95658"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-95667",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-22",
      "title": "MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95667"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-95679",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP Unauthenticated Blind SSRF via XML Body Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95679"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-95754",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP: Disabled-user check ineffective in pre-authentication TOTP login branch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95754"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-11389",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11389"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-18458",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18458"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-18626",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18626"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-79312",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-384",
      "title": "webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation after authentication, so a fixed session_id keeps the authenticated state.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79312"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-95624",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tauri",
      "product": "tauri-plugin-updater",
      "cwe": "CWE-284",
      "title": "Tauri framework v2 malicious downgrade via allow_downgrades from frontend code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95624"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-63278",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-200",
      "title": "Package URLs can be used to exfiltrate arbitrary INI file values and environment variables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63278"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-65129",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-295",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65129"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-85288",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-78",
      "title": "Notepad++: Shortcuts.xml macro HMAC bypass still reachable via the \"Run a Macro Multiple Times\" dialog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85288"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-65125",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-73",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65125"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-16426",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-918",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16426"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-17465",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-400",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17465"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-18114",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-22",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18114"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-18124",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-522",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18124"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-18132",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-862",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18132"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-18156",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-862",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18156"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-18170",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-770",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18170"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-57576",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plone",
      "product": "plone.app.dexterity",
      "cwe": "CWE-400",
      "title": "plone.app.dexterity and plone.app.contenttypes have a Denial of Service due to excessive title or description length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57576"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-65112",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-400",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65112"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-65115",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-400",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65115"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-75517",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "novuhq",
      "product": "novu",
      "cwe": "CWE-639",
      "title": "Novu: Cross-Environment Integration Manipulation (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75517"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-75638",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75638"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-77252",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-284",
      "title": "MCP Atlassian: JIRA_PROJECTS_FILTER and CONFLUENCE_SPACES_FILTER can be bypassed in search tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77252"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-77266",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77266"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-77269",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77269"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-77270",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-22",
      "title": "MCP Atlassian: Arbitrary File Read via Upload Attachment Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77270"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-77399",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "collective",
      "product": "icalendar",
      "cwe": "CWE-400",
      "title": "icalendar: Denial of service via unbounded VALARM REPEAT expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77399"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-79913",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-697",
      "title": "Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79913"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-83600",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-193",
      "title": "Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, crashing parent agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83600"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-83601",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-190",
      "title": "Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer overflow and out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83601"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-83602",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-284",
      "title": "Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist controls via HTTP_ACL_NOCHECK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83602"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-92928",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenEye",
      "product": "Apex Network Video Recorder (NVR)",
      "cwe": "CWE-798",
      "title": "OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92928"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-96260",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-789",
      "title": "Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96260"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-83805",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nautobot",
      "product": "nautobot",
      "cwe": "CWE-285",
      "title": "Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83805"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-94384",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "amazon-connect-salesforce-lambda",
      "cwe": "CWE-862",
      "title": "Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94384"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-84301",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-918",
      "title": "FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84301"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-86805",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-367",
      "title": "AT_SECURE programs may load attacker-controlled code via $ORIGIN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86805"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-88010",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-208",
      "title": "Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88010"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-15915",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-552",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15915"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-83964",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-295",
      "title": "Adobe Connect | Improper Certificate Validation (CWE-295)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83964"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-92930",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenEye",
      "product": "Apex Network Video Recorder (NVR)",
      "cwe": "CWE-330",
      "title": "OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92930"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-48361",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Connect",
      "cwe": "CWE-79",
      "title": "Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48361"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-77250",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-312",
      "title": "MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77250"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-86062",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-79",
      "title": "LightRAG: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86062"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-75101",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-639",
      "title": "Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75101"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2025-36084",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-327",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36084"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-65124",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-91",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65124"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-77265",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-918",
      "title": "MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77265"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-85725",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-208",
      "title": "LightRAG: Plaintext Passwords Compared Without Constant-Time Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85725"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-94570",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-1287",
      "title": "CVE-2026-94570",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94570"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-95623",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tauri",
      "product": "tauri-plugin-http",
      "cwe": "CWE-918",
      "title": "Tauri framework v2 SSRF Protection Bypass via HTTP Redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95623"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-75633",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75633"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-75656",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-125",
      "title": "Bridge | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75656"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-76192",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-476",
      "title": "InDesign Desktop | NULL Pointer Dereference (CWE-476)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76192"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-76804",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectdiscovery",
      "product": "nuclei",
      "cwe": "CWE-284",
      "title": "Nuclei: Local File Read via Workflow File-Protocol Gate Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76804"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-77268",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-732",
      "title": "MCP Atlassian: Insecure File Permissions on OAuth Token Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77268"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-79767",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gardener",
      "product": "gardener",
      "cwe": "CWE-863",
      "title": "Gardener: Authorization Bypass via Group Subject Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79767"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-81878",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-190",
      "title": "radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81878"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-81879",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-125",
      "title": "radare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81879"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-81880",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-400",
      "title": "radare2: Uncontrolled resource consumption in radare2 PEF loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81880"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-81885",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-770",
      "title": "radare2: Infinite relocation-chain loop causes denial of service in radare2 NE parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81885"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-81886",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-770",
      "title": "radare2: Uncontrolled memory allocation in radare2 dmp64 parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81886"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-84396",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-476",
      "title": "InDesign Desktop | NULL Pointer Dereference (CWE-476)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84396"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-86056",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-476",
      "title": "Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86056"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-89277",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-190",
      "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89277"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-95271",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-287",
      "title": "dgtlmoon changedetection.io Authentication Hook flask_app.py check_authentication improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95271"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-95500",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JosephChuks",
      "product": "php-file-manager-with-code-editor",
      "cwe": "CWE-284",
      "title": "JosephChuks php-file-manager-with-code-editor Save codeEditor.php file_put_contents unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95500"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-95656",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-918",
      "title": "dgtlmoon changedetection.io Preview Endpoint __init__.py add_watch_ui_snapshot server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95656"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-95819",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anirbandutta9",
      "product": "College-Notes-Gallery",
      "cwe": "CWE-74",
      "title": "anirbandutta9 College-Notes-Gallery login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95819"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-96259",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-918",
      "title": "Mattermost server-side request forgery via OAuth endpoints configurable by a System Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96259"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-18133",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-22",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18133"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-18153",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-327",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18153"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-63272",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-125",
      "title": "Heap buffer overflow in WMF text record import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63272"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-63273",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow in PDF import encryption handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63273"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-63274",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-125",
      "title": "Heap buffer overflow in PDF import stream handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63274"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-63275",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-787",
      "title": "Stack buffer overflow in CFF font hint handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63275"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-63276",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-787",
      "title": "Stack buffer overflow in CFF to Type 1 font conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63276"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-63279",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-125",
      "title": "Out of bounds read in PICT image import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63279"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-77272",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-79",
      "title": "MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77272"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-83801",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nautobot",
      "product": "nautobot",
      "cwe": "CWE-79",
      "title": "Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83801"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-90462",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-280",
      "title": "Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90462"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-91129",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-918",
      "title": "Home Assistant: mDNS Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91129"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2025-12767",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-770",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12767"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-17620",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-523",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17620"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-56682",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-307",
      "title": "9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56682"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-63386",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sunnyadn",
      "product": "js-toml",
      "cwe": "CWE-674",
      "title": "js-toml: Uncontrolled recursion in `load()` causes `RangeError` (stack exhaustion) on deeply nested input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63386"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-65829",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joniles",
      "product": "mpxj",
      "cwe": "CWE-22",
      "title": "MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65829"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-75511",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "novuhq",
      "product": "novu",
      "cwe": "CWE-918",
      "title": "Novu: Server-Side Request Forgery (SSRF) via Chat Provider Webhook URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75511"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-76716",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": "CWE-770",
      "title": "Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76716"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-76717",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "ALE",
      "cwe": "CWE-200",
      "title": "Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76717"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-76803",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectdiscovery",
      "product": "nuclei",
      "cwe": "CWE-284",
      "title": "Nuclei: Local File Read via MySQL Client Sandbox Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76803"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-76805",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectdiscovery",
      "product": "nuclei",
      "cwe": "CWE-200",
      "title": "Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76805"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-76910",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unleash",
      "product": "unleash",
      "cwe": "CWE-639",
      "title": "Unleash: Clone-feature lets a user copy a feature from a project they cannot read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76910"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-77249",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sooperset",
      "product": "mcp-atlassian",
      "cwe": "CWE-918",
      "title": "MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permission lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77249"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-85709",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-209",
      "title": "LightRAG: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85709"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-88020",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autonomy Logic",
      "product": "OpenPLC Runtime",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88020"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-90990",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-93",
      "title": "Livestatus injection via monitoring filter values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90990"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-92882",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-522",
      "title": "Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92882"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-92929",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenEye",
      "product": "Apex Network Video Recorder (NVR)",
      "cwe": "CWE-290",
      "title": "OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92929"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-93341",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebWizards",
      "product": "MarketKing",
      "cwe": "CWE-862",
      "title": "MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93341"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-93342",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebWizards",
      "product": "MarketKing",
      "cwe": "CWE-862",
      "title": "MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93342"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-95671",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/add",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95671"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-95674",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP EventsController queryEnrichment allows querying unavailable or legacy modules without validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95674"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-95683",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-639",
      "title": "MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95683"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-95685",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-862",
      "title": "MISP Missing Authorization on replaceSuggestionInReport Event Report Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95685"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-95693",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-22",
      "title": "MISP Information Disclosure via Forged Upload Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95693"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-95697",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-862",
      "title": "MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95697"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-95698",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-22",
      "title": "MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95698"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-95805",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-285",
      "title": "MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95805"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-95812",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-79",
      "title": "ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95812"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-95813",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e621ng",
      "product": "e621ng",
      "cwe": "CWE-601",
      "title": "e621ng before 26.09.16 Open Redirect via URL Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95813"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-95829",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TDuckCloud",
      "product": "tduck-platform",
      "cwe": "CWE-89",
      "title": "TDuckCloud tduck-platform Pagination Inner Interceptor MybatisPlusConfig.java PaginationInnerInterceptor.concatOrderBy sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95829"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-95830",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theRealSain",
      "product": "Pixtream",
      "cwe": "CWE-434",
      "title": "theRealSain Pixtream post_upload.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95830"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-95833",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Leave Management System",
      "cwe": "CWE-89",
      "title": "itsourcecode Leave Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95833"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-75510",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "novuhq",
      "product": "novu",
      "cwe": "CWE-79",
      "title": "Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75510"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-95661",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95661"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-95665",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95665"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-95701",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-22",
      "title": "MISP Path Traversal via Organization Name in Org-Statistics Logo Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95701"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-95703",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95703"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-65117",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-259",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65117"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-65126",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-841",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65126"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-95659",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-20",
      "title": "MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95659"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-95682",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MISP",
      "product": "MISP",
      "cwe": "CWE-79",
      "title": "MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95682"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-76802",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectdiscovery",
      "product": "nuclei",
      "cwe": "CWE-78",
      "title": "Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76802"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-79315",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the browser decodes the entities before the client-side framework evaluates the content as a JavaScript expression. A logged-in panel user who visits a crafted URL allows arbitrary script execution in the same-origin context of the management page, enabling data theft and unauthorized actions through the victim's session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79315"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-18161",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-778",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18161"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-75634",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75634"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-76194",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Content Credentials Rust SDK",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76194"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-77425",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unleash",
      "product": "unleash",
      "cwe": "CWE-639",
      "title": "Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77425"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-95666",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-770",
      "title": "Unbounded post ID array in the bulk reactions endpoint allows denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95666"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-65127",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Infrastructure Controller",
      "cwe": "CWE-1258",
      "title": "NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65127"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-77637",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-862",
      "title": "Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77637"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-18173",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-295",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18173"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-95818",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The GNU C Library",
      "product": "glibc",
      "cwe": "CWE-121",
      "title": "AT_SECURE program buffer overflow via $ORIGIN processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95818"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-92706",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "darkreader",
      "product": "darkreader",
      "cwe": "CWE-200",
      "title": "Dark Reader: Ability to request icon-like bitmap data from certain local web servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92706"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-81881",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-125",
      "title": "radare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81881"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-81882",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-125",
      "title": "radare2: Missing string termination causes heap out-of-bounds read in radare2 bplist parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81882"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-81883",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-125",
      "title": "radare2: Out-of-bounds Read at the end of string in the LUA 5.3 bytecode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81883"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-95270",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-203",
      "title": "dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95270"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-95272",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-22",
      "title": "dgtlmoon changedetection.io Screenshot flask_app.py static_content path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95272"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-81884",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-125",
      "title": "radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81884"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-62364",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "wlc",
      "cwe": "CWE-200",
      "title": "wlc may disclose API tokens to project-configured URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62364"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-86698",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hexpm",
      "product": "hexpm",
      "cwe": "CWE-613",
      "title": "Refresh tokens accepted as private repository credentials at the CDN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86698"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-76909",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unleash",
      "product": "unleash",
      "cwe": "CWE-79",
      "title": "Unleash: CR-approval email renders user-controlled raw HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76909"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-95273",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "changedetection.io",
      "cwe": "CWE-22",
      "title": "dgtlmoon changedetection.io visual_selector_data flask_app.py static_content path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95273"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-95396",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-79",
      "title": "sfturing hosp_order Public Search Handlers HospitalController.java cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95396"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-95660",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moonshot AI",
      "product": "Kimi Code",
      "cwe": "CWE-77",
      "title": "Moonshot AI Kimi Code MCP Configuration Loader config-loader.ts os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95660"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-95820",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anirbandutta9",
      "product": "College-Notes-Gallery",
      "cwe": "CWE-284",
      "title": "anirbandutta9 College-Notes-Gallery userprofile.php admin1 unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95820"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-95828",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mstfakts",
      "product": "College-Management-System",
      "cwe": "CWE-384",
      "title": "Mstfakts College-Management-System Authentication server.php session_start session fixiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95828"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-95657",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgtlmoon",
      "product": "Changedetection.io",
      "cwe": "CWE-79",
      "title": "dgtlmoon Changedetection.io Visual Selector visual-selector.js setCurrentSelectedText cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95657"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-95501",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mtrano",
      "product": "APENCMS",
      "cwe": "CWE-74",
      "title": "mtrano APENCMS Template weasel.php eval code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95501"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-37603",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37603"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-37604",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37604"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-75432",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75432"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-79311",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79311"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-79314",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The update path fails to verify that the target resource belongs to the requesting session user, allowing unauthorized cross-user modification of data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79314"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-88339",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in application crash and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88339"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-88340",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88340"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-88341",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88341"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-88344",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan loop in lex() advances past the end of the input buffer and dereferences the out-of-bounds pointer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88344"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-88345",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string scanning logic in lex() dereferences the input pointer after it has reached the end of the buffer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88345"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-88350",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88350"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-88414",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88414"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-88415",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` is excluded from the global XSS filter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88415"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-88416",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88416"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-88418",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88418"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-88624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88624"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-89281",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache HTTP Server Project",
      "product": "Apache Lounge Windows",
      "cwe": null,
      "title": "CVE-2026-89281",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89281"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-89282",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache HTTP Server Project",
      "product": "Apache Lounge Windows",
      "cwe": null,
      "title": "CVE-2026-89282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89282"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-94574",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU Wget (Windows Builds)",
      "product": "Wget",
      "cwe": null,
      "title": "CVE-2026-94574",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94574"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-85102",
      "detail": "ADDED TO KEV — CVE-2026-85102 (checkpoint Quantum Security Gateway). Remediation due September 25, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-93616",
      "detail": "ADDED TO KEV — CVE-2026-93616 (checkpoint Quantum Security Management). Remediation due September 25, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-93952",
      "detail": "ADDED TO KEV — CVE-2026-93952 (Arista Networks VeloCloud Orchestrator (VCO) On-Prem). Remediation due September 25, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-94127",
      "detail": "ADDED TO KEV — CVE-2026-94127 (F5 BIG-IP). Remediation due September 25, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2019-25776",
      "detail": "EXPLOIT PUBLISHED — CVE-2019-25776 (Weaver Network Co., Ltd. E-cology). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-6851",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-6851. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-6134",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-6134 (Red Hat build of Keycloak 22). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-6563",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-6563 (Red Hat Single Sign-On 7.6 for RHEL 7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44253",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44253 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55191",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55191 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55192",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55192 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55564",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55564 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5704",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63652",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63652 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7273",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7273 (Zyxel GS1900-48HPv2 firmware). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91854",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91854 (code-projects Record Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92221 (gedelumbung HospitalManagement). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92385",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92385 (SourceCodester Online Food Ordering System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92475",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92475 (GPAC). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92526 (itsourcecode Leave Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92993",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92993 (Dromara mayfly-go). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93311",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93311 (Freedesktop Poppler). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93312",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93312 (Freedesktop Poppler). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93532",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93532 (gedelumbung HospitalManagement). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93738",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93738 (Totolink A3002MU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93741",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93741 (Totolink A3002MU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93954",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93954 (grimmory-tools grimmory). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93957",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93957 (olivier-ls PHP-FTS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93959",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93959 (SourceCodester Online Reviewer Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93960",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93960 (Pixelfed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93962",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93962 (Kamailio). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93964",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93964 (NginxProxyManager nginx-proxy-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93974",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93974 (SourceCodester Online Reviewer Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93979",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93979 (code-projects Internship Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93984",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93984 (Openpanel-dev openpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94015 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94016 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94032",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94032 (itsourcecode Leave Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94037",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94037 (00Kisumi00 mcp-file-analyzer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94042",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94042 (AdithyaYelloju Restaurant Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94047",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94047 (samanhappy MCPHub). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94089",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94089 (D-Link DIR-868L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94094",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94094 (OpenClaw). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94099",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94099 (Netcore NBR200V2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94110",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94110 (QCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94139",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94139 (Chengdu Feiyuxing Technology Feiyu Star Router). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94152",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94152 (Omega Solution FBP Fulfillment by People). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94413",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94413 (jishenghua jshERP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94497 (jishenghua jshERP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94533",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94533 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94534",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94534 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94535",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94535 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-39682",
      "detail": "DUE DATE PASSED — CVE-2025-39682 (Linux). CISA remediation deadline was September 21, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-39964",
      "detail": "DUE DATE PASSED — CVE-2025-39964 (Linux). CISA remediation deadline was September 21, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-53266",
      "detail": "DUE DATE PASSED — CVE-2026-53266 (Linux). CISA remediation deadline was September 21, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-4547",
      "detail": "RESCORED — CVE-2023-4547 (SPA-Cart eCommerce CMS). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-4548",
      "detail": "RESCORED — CVE-2023-4548 (SPA-Cart eCommerce CMS). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-6134",
      "detail": "RESCORED — CVE-2023-6134 (Red Hat build of Keycloak 22). CVSS 4.6 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-6927",
      "detail": "RESCORED — CVE-2023-6927 (Red Hat build of Keycloak 22). CVSS 4.6 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-24075",
      "detail": "RESCORED — CVE-2026-24075 (Qualcomm, Inc. Snapdragon). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-25261",
      "detail": "RESCORED — CVE-2026-25261 (Qualcomm, Inc. Snapdragon). CVSS 6.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-25278",
      "detail": "RESCORED — CVE-2026-25278 (Qualcomm, Inc. Snapdragon). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55564",
      "detail": "RESCORED — CVE-2026-55564 (FreeRDP). CVSS 5.4 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55748",
      "detail": "RESCORED — CVE-2026-55748 (OpenStack Horizon). CVSS 6 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58381",
      "detail": "RESCORED — CVE-2026-58381 (Red Hat Enterprise Linux 6). CVSS 6.1 → 7.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69681",
      "detail": "RESCORED — CVE-2026-69681 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69688",
      "detail": "RESCORED — CVE-2026-69688 (Microsoft Windows 10 Version 1607). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69689",
      "detail": "RESCORED — CVE-2026-69689 (Microsoft Windows 10 Version 1809). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69706",
      "detail": "RESCORED — CVE-2026-69706 (Microsoft Windows 10 Version 1607). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69714",
      "detail": "RESCORED — CVE-2026-69714 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69717",
      "detail": "RESCORED — CVE-2026-69717 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69757",
      "detail": "RESCORED — CVE-2026-69757 (Microsoft Windows 10 Version 1809). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69761",
      "detail": "RESCORED — CVE-2026-69761 (Microsoft Windows 10 Version 1607). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69762",
      "detail": "RESCORED — CVE-2026-69762 (Microsoft Windows 10 Version 1809). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69775",
      "detail": "RESCORED — CVE-2026-69775 (Microsoft Windows 11 version 23H2). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71222",
      "detail": "RESCORED — CVE-2026-71222 (Red Hat Enterprise Linux 7). CVSS 5.3 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72931",
      "detail": "RESCORED — CVE-2026-72931 (Microsoft Windows 10 Version 1607). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72978",
      "detail": "RESCORED — CVE-2026-72978 (Microsoft Windows 10 Version 1607). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78620",
      "detail": "RESCORED — CVE-2026-78620 (Okta Access Gateway). CVSS 5.9 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78623",
      "detail": "RESCORED — CVE-2026-78623 (Okta Access Gateway). CVSS 7.7 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78626",
      "detail": "RESCORED — CVE-2026-78626 (Okta Access Gateway). CVSS 8.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78627",
      "detail": "RESCORED — CVE-2026-78627 (Okta Hyperdrive Integration Plugin). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78629",
      "detail": "RESCORED — CVE-2026-78629 (Okta Hyperdrive Agent). CVSS 5.6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78631",
      "detail": "RESCORED — CVE-2026-78631 (Okta Hyperdrive Agent). CVSS 5.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-93295",
      "detail": "RESCORED — CVE-2026-93295 (misp). CVSS 5.1 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-93296",
      "detail": "RESCORED — CVE-2026-93296 (misp). CVSS 5.1 → 8.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94109",
      "detail": "RESCORED — CVE-2026-94109 (openEQUELLA). CVSS 8.7 → 8.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94489",
      "detail": "RESCORED — CVE-2026-94489 (OctoPrint). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2026-95511",
      "detail": "REJECTED — CVE-2026-95511 (Red Hat Enterprise Linux 10). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-10832",
      "detail": "PATCH SHIPPED — CVE-2026-10832 (Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10). Fixed in Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 0:2.40.0-8.redhat_00024.1.el10eap."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-14180",
      "detail": "PATCH SHIPPED — CVE-2026-14180 (Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10). Fixed in Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 0:2.40.0-8.redhat_00024.1.el10eap."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-19730",
      "detail": "PATCH SHIPPED — CVE-2026-19730 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 7:5.8.2-9.el10_2."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-5680",
      "detail": "PATCH SHIPPED — CVE-2026-5680 (Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10). Fixed in Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 0:2.40.0-8.redhat_00024.1.el10eap."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-84217",
      "detail": "PATCH SHIPPED — CVE-2026-84217 (Mamunur Rashid Classified Listing). Fixed in Classified Listing 6.1.5."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-85511",
      "detail": "PATCH SHIPPED — CVE-2026-85511 (Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10). Fixed in Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 0:2.40.0-8.redhat_00024.1.el10eap."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-6851",
      "detail": "ENRICHED — CVE-2020-6851. Received CVSS 7.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
