{
  "day": "2026-09-23",
  "boundary": "UTC calendar day",
  "published_count": 472,
  "by_severity": {
    "CRITICAL": 42,
    "HIGH": 188,
    "MEDIUM": 196,
    "LOW": 40
  },
  "kev_count": 0,
  "exploit_reference_count": 4,
  "awaiting_enrichment_count": 6,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-15027",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.02173,
      "epss_percentile": 0.81535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Changing",
      "product": "CGServiSign",
      "cwe": "CWE-78",
      "title": "Changing｜CGServiSign - OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15027"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-96257",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01038,
      "epss_percentile": 0.62485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fast",
      "product": "FAC1203R Gigabit Edition",
      "cwe": "CWE-119",
      "title": "Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96257"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-31377",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00647,
      "epss_percentile": 0.49622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Doris",
      "cwe": "CWE-287",
      "title": "Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31377"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-96272",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00541,
      "epss_percentile": 0.44446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket v5 before 5.5.3-#182 SQL Injection via search_result.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96272"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-89425",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00533,
      "epss_percentile": 0.43979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-core",
      "cwe": "CWE-400",
      "title": "jackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89425"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-93368",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.42197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "travispluse",
      "product": "Rename wp-login.php to anything you want",
      "cwe": "CWE-89",
      "title": "Rename wp-login.php to anything you want <= 2.0.1 - Unauthenticated SQL Injection via 'log' (Username) Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93368"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-91776",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.41107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-400",
      "title": "jackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91776"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-91777",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.41106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-400",
      "title": "jackson-databind: quadratic forward-reference completion in Collection and Map deserializers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91777"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-96454",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.40845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tw93",
      "product": "Pake",
      "cwe": "CWE-862",
      "title": "Pake grants unrestricted IPC access to every HTTPS origin loaded in generated applications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96454"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-95626",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.39937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tauri",
      "product": "tauri",
      "cwe": "CWE-79",
      "title": "Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95626"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-95957",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0047,
      "epss_percentile": 0.39872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Smart Attendance System with QR Code Scanner",
      "cwe": "CWE-79",
      "title": "SourceCodester Smart Attendance System with QR Code Scanner Self-Registration student_signup.php prepend cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95957"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-96258",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00449,
      "epss_percentile": 0.38388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onSite internet GmbH",
      "product": "Auktion NG Auktionssoftware",
      "cwe": "CWE-79",
      "title": "onSite internet GmbH Auktion NG Auktionssoftware Public Password Reset Endpoint forgotpasswd.html cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96258"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-95924",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95924"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-95925",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php update sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95925"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-95926",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System btn_functions.php update sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95926"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-95927",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Reviewer Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Reviewer Management System exam-delete.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95927"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-95930",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00427,
      "epss_percentile": 0.36614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iFlytek",
      "product": "astron-agent",
      "cwe": "CWE-918",
      "title": "iFlytek astron-agent debugToolV2 API endpoint UrlCheckTool.checkUrl server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95930"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-19438",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.35094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "Mint Workbench I",
      "cwe": "CWE-22",
      "title": "Mint Workbench I Path traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19438"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-95929",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.32913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iFlytek",
      "product": "astron-agent",
      "cwe": "CWE-74",
      "title": "iFlytek astron-agent getBotList API endpoint ChatBotMarketMapper.xml sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95929"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-96271",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "photoview",
      "product": "photoview",
      "cwe": "CWE-639",
      "title": "Photoview through 2.4.0 Authorization Bypass via shareAlbum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96271"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-6831",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.29141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vsourz1td",
      "product": "Advanced Contact form 7 DB",
      "cwe": "CWE-862",
      "title": "Advanced Contact form 7 DB <= 2.1.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure via 'acf7db' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6831"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-5924",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.28604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "Getwid – Gutenberg Blocks",
      "cwe": "CWE-79",
      "title": "Getwid <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5924"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-91797",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.2824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-73",
      "title": "Foxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91797"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-95627",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.27325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tauri",
      "product": "tauri-plugin-dialog",
      "cwe": "CWE-732",
      "title": "Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95627"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-95897",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.27268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Dask",
      "cwe": "CWE-20",
      "title": "Dask Loader core.py from_npy_stack deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95897"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-95928",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.27268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "recommenders-team",
      "product": "recommenders",
      "cwe": "CWE-20",
      "title": "recommenders-team recommenders Dict Loading mind_iterator.py pickle.load deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95928"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-95868",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00333,
      "epss_percentile": 0.26747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdithyaYelloju",
      "product": "Restaurant-Management-System",
      "cwe": "CWE-74",
      "title": "AdithyaYelloju Restaurant-Management-System Search Form display_menu.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95868"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-42801",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASR",
      "product": "Crane，Falcon",
      "cwe": "CWE-476",
      "title": "Deference after null check in as_rrc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42801"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-96443",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Doris",
      "cwe": "CWE-829",
      "title": "Apache Doris: JDBC driver URL validation bypass leads to remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96443"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-50227",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "NitroSense V5",
      "cwe": "CWE-78",
      "title": "MQTT WebSocket Command Execution Vulnerability in NitroSense",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50227"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-75799",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00235,
      "epss_percentile": 0.14799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YAHMAN Add-ons",
      "cwe": "CWE-94",
      "title": "YAHMAN Add-ons < 0.9.31 - Unauthenticated Arbitrary File Upload via Blog Card Cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75799"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2022-4997",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "jet-form-builder-stripe-gateway",
      "cwe": "CWE-89",
      "title": "JetFormBuilder Stripe Gateway < 1.1.0 - Unauthenticated Blind SQLi via Payment Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-4997"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-91789",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-787",
      "title": "Foxit PDF Editor/Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91789"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-91794",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-787",
      "title": "Foxit PDF Editor/Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91794"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-91024",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking Manager",
      "cwe": "CWE-89",
      "title": "Booking Manager < 2.1.21 - Author+ SQLi via ICS Import Feed UID (sync_gid)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91024"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-95625",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tauri",
      "product": "tauri-plugin-updater",
      "cwe": "CWE-354",
      "title": "Tauri framework v2 missing updater signature version number validation can be exploited into forced downgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95625"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-91073",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Subscribe Forms",
      "cwe": "CWE-79",
      "title": "Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91073"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-91852",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.1185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Sling XSS",
      "cwe": "CWE-79",
      "title": "Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91852"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-14321",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.1166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "divi-dash",
      "cwe": "CWE-400",
      "title": "Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14321"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-15696",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Real3D Flipbook",
      "cwe": "CWE-79",
      "title": "Real3D Flipbook Lite < 5.4 - Author+ Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15696"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-85006",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "HappyAddons for Elementor",
      "cwe": "CWE-79",
      "title": "Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85006"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-88997",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JSM Show Post Metadata",
      "cwe": "CWE-79",
      "title": "JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88997"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-91801",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-22",
      "title": "Foxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91801"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-86842",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Real3D Flipbook",
      "cwe": "CWE-862",
      "title": "Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86842"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-73192",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Sling XSS",
      "cwe": "CWE-79",
      "title": "Apache Sling XSS: XSS possible through XSSAPI.getValidHref()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73192"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-91928",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Sling XSS",
      "cwe": "CWE-79",
      "title": "Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91928"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-91999",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Sling XSS",
      "cwe": "CWE-79",
      "title": "Apache Sling XSS: Improper escaping in the XSS Webconsole plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91999"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-87979",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paymob for WooCommerce",
      "cwe": "CWE-862",
      "title": "Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87979"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-93511",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Premium Packages",
      "cwe": "CWE-290",
      "title": "Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93511"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-86608",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.09967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Recipe Maker",
      "cwe": "CWE-400",
      "title": "WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86608"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-84026",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-200",
      "title": "Directorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST Users Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84026"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-84168",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Hide Login",
      "cwe": "CWE-200",
      "title": "Easy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84168"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-84741",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "The Events Calendar",
      "cwe": "CWE-200",
      "title": "The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84741"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-86783",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Post Grid Gutenberg Blocks",
      "cwe": "CWE-200",
      "title": "PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86783"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-88929",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Badge, Label, Countdown Timer for WooCommerce",
      "cwe": "CWE-200",
      "title": "Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88929"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-89331",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentBoards",
      "cwe": "CWE-200",
      "title": "FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Public Board Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89331"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-90985",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.09968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPC Smart Compare for WooCommerce",
      "cwe": "CWE-200",
      "title": "WPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protected Product Description Disclosure via woosc_load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90985"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-93528",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "NP Quote Request for WooCommerce",
      "cwe": "CWE-200",
      "title": "NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93528"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-82331",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00195,
      "epss_percentile": 0.09537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache BuildStream",
      "cwe": "CWE-59",
      "title": "Apache BuildStream: tar source extraction escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82331"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-84742",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "The Events Calendar",
      "cwe": "CWE-863",
      "title": "The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84742"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-94251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Sling Security Bundle",
      "cwe": "CWE-693",
      "title": "Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94251"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-18365",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "zportals",
      "cwe": "CWE-200",
      "title": "Zportals < 6.4.2 - Subscriber+ User Email Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18365"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-86602",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Recipe Maker",
      "cwe": "CWE-200",
      "title": "WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86602"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-86603",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Recipe Maker",
      "cwe": "CWE-200",
      "title": "WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86603"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-92001",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Sling XSS",
      "cwe": "CWE-776",
      "title": "Apache Sling XSS: Missing parser resource limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92001"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-80342",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Payment Plugins for PayPal WooCommerce",
      "cwe": "CWE-639",
      "title": "Payment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80342"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-77765",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Better Payment",
      "cwe": "CWE-284",
      "title": "Better Payment < 2.3.4 - Unauthenticated Payment Amount Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77765"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-83555",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Email Subscribers & Newsletters",
      "cwe": "CWE-862",
      "title": "Email Subscribers by Icegram Express < 5.9.35 - Unauthenticated Subscription Status Change via Missing Token Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83555"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-86785",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Social Commerce for WooCommerce",
      "cwe": "CWE-862",
      "title": "Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86785"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-91791",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91791"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-91799",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit Editor/Reader Array resetForm Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91799"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-91815",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-787",
      "title": "Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91815"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-82843",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0018,
      "epss_percentile": 0.07859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP OAuth Server ( Login with WordPress )",
      "cwe": "CWE-287",
      "title": "WP OAuth Server < 6.4.0 - Subscriber+ Cross-User Account Takeover via OIDC ID Token Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82843"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-93508",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WC Fields Factory",
      "cwe": "CWE-862",
      "title": "WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93508"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-16264",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletters",
      "cwe": "CWE-639",
      "title": "Newsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16264"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-84098",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-863",
      "title": "Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84098"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-84150",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-639",
      "title": "Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84150"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-84046",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-918",
      "title": "Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84046"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-87981",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paymob for WooCommerce",
      "cwe": "CWE-862",
      "title": "Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87981"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-18364",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "zportals",
      "cwe": "CWE-862",
      "title": "Zportals < 6.4.2 - Subscriber+ Arbitrary Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18364"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-77766",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-639",
      "title": "Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77766"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-81339",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS < 3.7.50 - Subscriber+ Quiz Attempt Grade Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81339"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-84027",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Directorist: AI-Powered Business Directory, Listings & Classified Ads",
      "cwe": "CWE-862",
      "title": "Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84027"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-91025",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking Manager",
      "cwe": "CWE-639",
      "title": "Booking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91025"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-93510",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Points and Rewards for WooCommerce",
      "cwe": "CWE-862",
      "title": "Points and Rewards for WooCommerce < 2.10.4 - Subscriber+ Arbitrary Points and Wallet Balance Manipulation via assign_claim_points",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93510"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-84743",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.0786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "The Events Calendar",
      "cwe": "CWE-863",
      "title": "The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84743"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-87074",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Forminator Forms",
      "cwe": "CWE-862",
      "title": "Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87074"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-90951",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paid Membership Subscriptions",
      "cwe": "CWE-863",
      "title": "Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_payment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90951"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-93507",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WC Fields Factory",
      "cwe": "CWE-862",
      "title": "WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93507"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-87069",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Forminator Forms",
      "cwe": "CWE-862",
      "title": "Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87069"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-91077",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Booking Manager for WooCommerce",
      "cwe": "CWE-284",
      "title": "Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disclosure via mpwem_load_event_list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91077"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-50228",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "NitroSense V5",
      "cwe": "CWE-489",
      "title": "Electron DevTools Arbitrary Code Execution Vulnerability in NitroSense",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50228"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-92378",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NT-ware",
      "product": "uniFLOW Online",
      "cwe": "CWE-613",
      "title": "uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92378"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-91796",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-693",
      "title": "Foxit PDF Editor/Reader importIcon NTLM Response Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91796"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-96273",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NationalSecurityAgency",
      "product": "ghidra",
      "cwe": "CWE-460",
      "title": "Ghidra before 12.1.4 Denial of Service via Crafted Database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96273"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-91814",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-347",
      "title": "Security vulnerability: Foxit PDF Editor/Reader Fails to Detect Modifications to Signed Documents Displaying Newly Added Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91814"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-91790",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91790"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-91792",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91792"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-91793",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91793"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-91802",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-787",
      "title": "Foxit PDF Editor/Reader — Heap Buffer Overflow in WebP Image Decoding via Bitmap Stride Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91802"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-91804",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-787",
      "title": "Foxit PDF Editor/Reader Out-of-bounds Write Vulnerability While Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91804"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-91805",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.0676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Use-after-free Vulnerability in Foxit PDF Editor/Reader Page-tree Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91805"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-91806",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91806"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-91809",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91809"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-91811",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-787",
      "title": "Foxit PDF Editor/Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91811"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-91816",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91816"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-91818",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91818"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-91803",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-427",
      "title": "Security Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Path Hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91803"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-95958",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.0559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JusticeRage",
      "product": "Manalyze",
      "cwe": "CWE-189",
      "title": "JusticeRage Manalyze PE Parser pe.cpp _parse_relocations integer underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95958"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-91807",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91807"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-91808",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91808"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-91810",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91810"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-91817",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91817"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-91800",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-732",
      "title": "Foxit PDF Editor installer local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91800"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-79616",
      "cvss_base": 0.6,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "qt",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79616"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-91798",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-732",
      "title": "Foxit PDF Editor/Reader Updater Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91798"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-81338",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-345",
      "title": "MasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course Discussions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81338"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-91788",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-668",
      "title": "Foxit PDF Editor/Reader Missing Authorization Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91788"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-91813",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-367",
      "title": "Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91813"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-94243",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Sling Security Bundle",
      "cwe": "CWE-346",
      "title": "Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94243"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-91812",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-295",
      "title": "Foxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91812"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-91795",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-822",
      "title": "Foxit PDF Editor/Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91795"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-59167",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JiHong88",
      "product": "suneditor",
      "cwe": "CWE-79",
      "title": "SunEditor: Critical XSS vulnerability - sanitizer bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59167"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-86708",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Applications Manager",
      "cwe": "CWE-321",
      "title": "Sensitive data exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86708"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-19599",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-78",
      "title": "Remote Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19599"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-77602",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenC3",
      "product": "cosmos",
      "cwe": "CWE-94",
      "title": "OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77602"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-84474",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
      "cwe": "CWE-807",
      "title": "Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84474"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-84502",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
      "cwe": "CWE-88",
      "title": "Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84502"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-84719",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
      "cwe": "CWE-862",
      "title": "Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84719"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-89078",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-415",
      "title": "Double Free in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89078"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-93577",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-190",
      "title": "Integer Overflow or Wraparound in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93577"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2025-63564",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63564"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-6721",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-78",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6721"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-6730",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-120",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6730"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-6928",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-416",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6928"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-76183",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-289",
      "title": "Apache Tomcat: Bypass of security constraints for WebSocket endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76183"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-86248",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-287",
      "title": "Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86248"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-96276",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-22",
      "title": "Flatpak: flatpak: arbitrary write in host context via flatpak build-init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96276"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-85724",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-155",
      "title": "Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85724"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-87898",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk extension \"Site Import\"",
      "cwe": "CWE-78",
      "title": "OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87898"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-87899",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-250",
      "title": "Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87899"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-87900",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "WP Toolkit for cPanel",
      "cwe": "CWE-88",
      "title": "Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87900"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-18872",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-79",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18872"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-93352",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plank",
      "product": "laravel-mediable",
      "cwe": "CWE-434",
      "title": "Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93352"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-95601",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WBW Plugins",
      "product": "Product Filter by WBW",
      "cwe": "CWE-89",
      "title": "WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95601"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-95848",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-636",
      "title": "Moquette fails open when configured authentication or authorization classes cannot load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95848"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-96560",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ModelTC",
      "product": "LightLLM",
      "cwe": "CWE-502",
      "title": "LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96560"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-96754",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96754"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-96755",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "orval @orval/effect 8.14.0 through 8.28.1 Code Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96755"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-96757",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "orval before 8.29.0 Code Injection via unescaped OpenAPI media-type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96757"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-96758",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "orval @orval/core before 8.28.0 Code Injection via Form-Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96758"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-96759",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "orval before 8.29.0 Code Injection via operationId",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96759"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-96770",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Temporal Technologies, Inc.",
      "product": "s2s-proxy",
      "cwe": "CWE-296",
      "title": "s2s-proxy accepts untrusted client certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96770"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-63132",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbao",
      "product": "openbao",
      "cwe": "CWE-208",
      "title": "OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63132"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-67404",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-295",
      "title": "RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67404"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-96756",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "orval-labs",
      "product": "orval",
      "cwe": "CWE-94",
      "title": "orval before 8.30.0 Code Injection via Factory Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96756"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-67231",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-295",
      "title": "RabbitMQ: Trust-store whitelist by Issuer+Serial only",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67231"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-75884",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
      "cwe": "CWE-184",
      "title": "Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75884"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-86246",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat Native",
      "cwe": "CWE-1188",
      "title": "Apache Tomcat Native: Insecure OpenSSL options enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86246"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-86350",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-444",
      "title": "Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86350"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-14913",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14913"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-18490",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-502",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18490"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-70125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": null,
      "title": "Microsoft Outlook Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70125"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-75825",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-306",
      "title": "Authentication Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75825"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-76978",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-78",
      "title": "Command Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76978"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-77601",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenC3",
      "product": "cosmos",
      "cwe": "CWE-78",
      "title": "OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77601"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-80379",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80379"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-80412",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80412"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-80423",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-200",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80423"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-80425",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80425"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-81537",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81537"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-86583",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "carazo",
      "product": "Import and export users and customers",
      "cwe": "CWE-266",
      "title": "Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86583"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-86677",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Applications Manager",
      "cwe": "CWE-89",
      "title": "Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86677"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-86678",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Applications Manager",
      "cwe": "CWE-639",
      "title": "Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86678"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-95847",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-99",
      "title": "Moquette client IDs can cause cross-session H2 durable-queue corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95847"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-96275",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-22",
      "title": "Flatpak: flatpak: arbitrary write access as root via extra-data extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96275"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-96455",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pollen Robotics",
      "product": "Reachy Mini",
      "cwe": "CWE-306",
      "title": "Reachy Mini daemon allows unauthenticated remote code execution through the app installation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96455"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-96775",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MLflow",
      "product": "MLflow",
      "cwe": "CWE-502",
      "title": "MLflow dspy bypasses pickle deserialization control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96775"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-96804",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MLflow",
      "product": "MLflow",
      "cwe": "CWE-502",
      "title": "CVE-2026-96804",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96804"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-55610",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InvoiceShelf",
      "product": "InvoiceShelf",
      "cwe": "CWE-639",
      "title": "InvoiceShelf has cross-company user read/update IDOR that enables cross-tenant account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55610"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-68492",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-426",
      "title": "An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the \"Plesk RESTful API\" extension from 2.4.2 before 2.4.7.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68492"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-82368",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-284",
      "title": "Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82368"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-82405",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-863",
      "title": "Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82405"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-84683",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-79",
      "title": "Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout html view via ansi osc 8 hyperlink sequences (javascript: anchor) enabling session takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84683"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-84691",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-134",
      "title": "Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx error log setting discloses django secret_key and database credentials to an administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84691"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-95842",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-248",
      "title": "Moquette uncaught MQTT command exceptions can terminate shared session event loops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95842"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-95843",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-20",
      "title": "Moquette malformed shared subscriptions can crash command processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95843"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-95844",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-674",
      "title": "Moquette deeply nested MQTT topics can cause stack exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95844"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-95845",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-770",
      "title": "Moquette unbounded per-session message queues allow memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95845"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-95846",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moquette-io",
      "product": "moquette",
      "cwe": "CWE-862",
      "title": "Moquette publishes Last-Will messages without enforcing write authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95846"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-96673",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Photoview",
      "product": "Photoview",
      "cwe": "CWE-89",
      "title": "Photoview through 2.4.0 SQL Injection via album download route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96673"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-82369",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-78",
      "title": "Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82369"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-82370",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-77",
      "title": "Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82370"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-86064",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-200",
      "title": "Klever-Go: /log controls global node logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86064"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-90901",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-74",
      "title": "Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90901"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-90904",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90904"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-93349",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frictionlessdata",
      "product": "frictionless-py",
      "cwe": "CWE-78",
      "title": "Frictionless OS Command Injection via explore Console Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93349"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-96656",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plex",
      "product": "Media Server",
      "cwe": "CWE-73",
      "title": "Plex Media Server arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96656"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-75131",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nm-l2tp",
      "product": "NetworkManager-l2tp",
      "cwe": "CWE-88",
      "title": "NetworkManager-l2tp Privilege Escalation via pppd Username Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75131"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-76086",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verbb",
      "product": "formie",
      "cwe": "CWE-862",
      "title": "Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76086"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-76648",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.7",
      "cwe": "CWE-862",
      "title": "Automation-controller: automation-controller-container: aap controller: copyapiview.post() missing read authorization check enables job template secret recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76648"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-79310",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the attacker can write to and later renders them through the precompiled template loader, the sandbox is bypassed and the attacker's code runs, resulting in arbitrary Python code execution and OS command execution on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79310"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-93527",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Live Copy Paste for Elementor",
      "cwe": "CWE-89",
      "title": "WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93527"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-93773",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nick van Wobbie",
      "product": "Mollie Forms",
      "cwe": "CWE-89",
      "title": "WordPress Mollie Forms plugin <= 2.11.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93773"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-94124",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "levelfourdevelopment",
      "product": "WP EasyCart",
      "cwe": "CWE-89",
      "title": "WordPress WP EasyCart plugin <= 5.9.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94124"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-5695",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microweber",
      "product": "Administration panel",
      "cwe": "CWE-434",
      "title": "Multiple vulnerabilities in the Microweber administration panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5695"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-82409",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-116",
      "title": "Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82409"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-19179",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-74",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19179"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-66079",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66079"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-67232",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-409",
      "title": "RabbitMQ: Web-MQTT decompression bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67232"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-68490",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-732",
      "title": "Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68490"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-76087",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verbb",
      "product": "formie",
      "cwe": "CWE-639",
      "title": "Formie: Unauthenticated users can overwrite incomplete submissions via submit action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76087"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-84486",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
      "cwe": "CWE-489",
      "title": "Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (allowany, routed without debug guard) allow advisory-lock starvation of job dispatch (dos)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84486"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-90899",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-200",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90899"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-90902",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-74",
      "title": "Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90902"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-96599",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isotope",
      "product": "isotope-core",
      "cwe": "CWE-330",
      "title": "Isotope eCommerce through 2.9.10 Weak Order Identifier Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96599"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-18181",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-321",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18181"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-19125",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lynn999",
      "product": "EthPress – Web3 Login",
      "cwe": "CWE-287",
      "title": "EthPress <= 2.3.5 - Unauthenticated Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19125"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-77762",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-362",
      "title": "Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77762"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-84787",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-250",
      "title": "Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84787"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-86683",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Applications Manager",
      "cwe": "CWE-20",
      "title": "Broken Authentication Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86683"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-94487",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PublishPress",
      "product": "PublishPress Capabilities",
      "cwe": "CWE-352",
      "title": "WordPress PublishPress Capabilities plugin <= 2.50.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94487"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-12974",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forcepoint",
      "product": "Forcepoint Security Engine (NGFW)",
      "cwe": "CWE-183",
      "title": "Security Policy Bypass in Forcepoint Security Engine (NGFW)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12974"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-6794",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-415",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6794"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-6935",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-427",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6935"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-96442",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-94",
      "title": "Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96442"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-96512",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-863",
      "title": "Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96512"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-96889",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Librsvg: use-after-free when xml includes have duplicated entities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96889"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-76089",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verbb",
      "product": "formie",
      "cwe": "CWE-200",
      "title": "Formie: Missing authorization on sent notification resend modal exposes submission PII",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76089"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-76979",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-91",
      "title": "XML Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76979"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-81208",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-522",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81208"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-81536",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-611",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81536"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-84499",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-209",
      "title": "Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84499"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-92470",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92470"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-12370",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-1336",
      "title": "Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12370"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-66070",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-942",
      "title": "RabbitMQ: CORS * reflects Origin with Allow-Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66070"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-77394",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenC3",
      "product": "cosmos",
      "cwe": "CWE-79",
      "title": "OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77394"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-84706",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-184",
      "title": "Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84706"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-86681",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Applications Manager",
      "cwe": "CWE-306",
      "title": "Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86681"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-94174",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebFactory",
      "product": "Email Log",
      "cwe": "CWE-89",
      "title": "WordPress Email Log plugin <= 2.63 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94174"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-95522",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "Easy Digital Downloads",
      "cwe": "CWE-89",
      "title": "WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95522"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-95593",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ben Roberts",
      "product": "Ultimeter",
      "cwe": "CWE-89",
      "title": "WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95593"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-96826",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shazzad Hossain Khan",
      "product": "W4 Post List",
      "cwe": "CWE-89",
      "title": "WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96826"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-6668",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PgBouncer",
      "cwe": "CWE-190",
      "title": "Integer overflow causes an infinite loop in packet buffer growth in PgBouncer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6668"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-15358",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-428",
      "title": "Path Traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15358"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-19888",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PgBouncer",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in SCRAM client-final-message parsing in PgBouncer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19888"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-59990",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typelevel",
      "product": "jawn",
      "cwe": "CWE-770",
      "title": "Jawn: Uncontrolled nesting depth in JSON parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59990"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-61695",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "square",
      "product": "wire",
      "cwe": "CWE-129",
      "title": "Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61695"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-61814",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typelevel",
      "product": "jawn",
      "cwe": "CWE-400",
      "title": "Jawn: Quadratic parsing effort in AsyncParser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61814"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-73591",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-540",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73591"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-75887",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-22",
      "title": "Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75887"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-77422",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jline",
      "product": "jline3",
      "cwe": "CWE-1333",
      "title": "JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77422"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-77423",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jline",
      "product": "jline3",
      "cwe": "CWE-1333",
      "title": "JLine: ReDoS in Built-in Less Viewer Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77423"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-77791",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-400",
      "title": "Apache Tomcat: DoS via busy wait during WebSocket close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77791"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-78383",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-770",
      "title": "Apache Tomcat: AJP DoS via missing request body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78383"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-79677",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-772",
      "title": "Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79677"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-86065",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-770",
      "title": "Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86065"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-86243",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat Native",
      "cwe": "CWE-126",
      "title": "Apache Tomcat Native: DoS via TLS handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86243"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-87022",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-130",
      "title": "Apache Tomcat: WebSocket message smuggling with per-message-deflate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87022"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-88830",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-131",
      "title": "Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88830"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-95513",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vcita",
      "product": "Online Booking & Scheduling Calendar for WordPress by vcita",
      "cwe": "CWE-862",
      "title": "WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.6.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95513"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-95604",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tangible",
      "product": "Loops & Logic",
      "cwe": "CWE-862",
      "title": "WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95604"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-96541",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-400",
      "title": "Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96541"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-18184",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-611",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18184"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-73588",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-306",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73588"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-76980",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-20",
      "title": "Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76980"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-86247",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat Native",
      "cwe": "CWE-366",
      "title": "Apache Tomcat Native: Client certificate requirements can be down-graded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86247"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-91775",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91775"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-92730",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-79",
      "title": "LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92730"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-94181",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Browser Company of New York",
      "product": "Arc",
      "cwe": "CWE-451",
      "title": "Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94181"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-94183",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Browser Company of New York",
      "product": "Arc Search",
      "cwe": "CWE-451",
      "title": "Address bar spoofing risk in affected Android versions of Arc Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94183"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-95676",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "AuthPoint Authentication Gateway",
      "cwe": "CWE-287",
      "title": "AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95676"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-96808",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flatpak",
      "product": "Flatpak",
      "cwe": "CWE-61",
      "title": "In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal. A malicious local user in an active local session could obtain two revokefs sessions via the system helper, create a symlink in one session pointing into the other session's directory, and retain a file descriptor through that symlink. This allowed the attacker to modify files belonging to a different revokefs session after they had been validated and imported by the system helper. In particular, an attacker could use this to tamper with ostree commit objects in the system repository after they passed signature verification, enabling root-controlled file writes to attacker-chosen paths and local root privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96808"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-18185",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-306",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18185"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-18875",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-74",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18875"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-66077",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-79",
      "title": "RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66077"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-75973",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-287",
      "title": "Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75973"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-78437",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-459",
      "title": "Apache Tomcat: HTTP/2 DoS via malformed request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78437"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-88832",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-787",
      "title": "Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88832"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-75886",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-441",
      "title": "Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75886"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-85475",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.7",
      "cwe": "CWE-96",
      "title": "Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote code execution in the control-plane rsyslog component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85475"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-90903",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90903"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-90905",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90905"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-93769",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Humhub",
      "product": "Humhub",
      "cwe": "CWE-79",
      "title": "HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93769"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-95603",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Victor Rodriguez",
      "product": "Reycob Product Import Export",
      "cwe": "CWE-502",
      "title": "WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95603"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-18177",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-862",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18177"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-67235",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67235"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-67238",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Atom-table exhaustion via reply-to queue name decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67238"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-82406",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-841",
      "title": "Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82406"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-84714",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-184",
      "title": "Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84714"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-84789",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-639",
      "title": "Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84789"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-84791",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine OpManager",
      "cwe": "CWE-639",
      "title": "Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84791"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-86679",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine Applications Manager",
      "cwe": "CWE-20",
      "title": "Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86679"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-93526",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Event Tickets",
      "cwe": "CWE-79",
      "title": "WordPress Event Tickets plugin <= 5.29.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93526"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-93622",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NicolasKulka",
      "product": "WPS Limit Login",
      "cwe": "CWE-79",
      "title": "WordPress WPS Limit Login plugin <= 1.5.9.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93622"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-93774",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jacob N. Breetvelt",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-79",
      "title": "WordPress WP Photo Album Plus plugin <= 9.3.02.002 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93774"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-94176",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kitae Park",
      "product": "Mang Board WP",
      "cwe": "CWE-79",
      "title": "WordPress Mang Board WP plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94176"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-94179",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Razorpay",
      "product": "Razorpay Payment Button",
      "cwe": "CWE-79",
      "title": "WordPress Razorpay Payment Button plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94179"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-95515",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kevin Stover",
      "product": "Ninja Forms",
      "cwe": "CWE-79",
      "title": "WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95515"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-95528",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mohammed Kaludi",
      "product": "Core Web Vitals & PageSpeed Booster",
      "cwe": "CWE-79",
      "title": "WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95528"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-95529",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Calculated Fields Form",
      "cwe": "CWE-79",
      "title": "WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95529"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-95590",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tainacan",
      "product": "Tainacan",
      "cwe": "CWE-89",
      "title": "WordPress Tainacan plugin <= 1.2.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95590"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-96609",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Robur",
      "product": "Albatross",
      "cwe": "CWE-770",
      "title": "Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer (1024 lines). It is not exploitable by unauthorized clients.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96609"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-96651",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plex",
      "product": "Media Server",
      "cwe": "CWE-22",
      "title": "Plex Media Server path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96651"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-82407",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-20",
      "title": "Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82407"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-96600",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isotope",
      "product": "isotope-core",
      "cwe": "CWE-89",
      "title": "Isotope eCommerce through 2.9.10 SQL Injection via Backend Callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96600"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-67228",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67228"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-67229",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67229"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-92284",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-770",
      "title": "Caddy: Unbounded body buffer via {http.request.body} placeholder — memory exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92284"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-92692",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sulu",
      "product": "sulu",
      "cwe": "CWE-89",
      "title": "Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92692"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-96611",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-190",
      "title": "FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds checking, allowing values exceeding INT_MAX to become negative. In read_image_grid(), accumulating these values causes signed integer overflow (undefined behavior per C17 section 6.5), which on x86 wraps to a small positive value, bypassing downstream validity checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96611"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-96654",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plex",
      "product": "Media Server",
      "cwe": "CWE-84",
      "title": "Plex Media Server URL injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96654"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-96751",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pmTicket",
      "product": "Project-Management-Software",
      "cwe": "CWE-89",
      "title": "pmTicket Project-Management-Software add_project.php setSync sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96751"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-96762",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "mooncake",
      "cwe": "CWE-639",
      "title": "kvcache-ai mooncake RPC Path UnmountSegment authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96762"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-61413",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-269",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61413"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-73587",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-295",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73587"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-96445",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-287",
      "title": "Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96445"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-88839",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-787",
      "title": "Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88839"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-84716",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-266",
      "title": "Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84716"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-84724",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-88",
      "title": "Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84724"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-18179",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-862",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18179"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-18180",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-89",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18180"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-73581",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-299",
      "title": "Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73581"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-77112",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Global IT Informatics Technology Services Inc.",
      "product": "Weoll",
      "cwe": "CWE-918",
      "title": "SSRF Leading to JWT Token Disclosure in Global IT Informatics' Weoll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77112"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-77421",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jline",
      "product": "jline3",
      "cwe": "CWE-1333",
      "title": "JLine: ReDoS in Nano Editor Regex Search Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77421"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-79304",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply an arbitrary absolute or out-of-scope path in the fileName JSON property. Because authorization validates only domainName and does not canonicalize or restrict fileName to that domain's home directory, the application returns the contents of files readable by the CyberPanel execution identity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79304"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-79306",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-scope file paths in the listOfFiles JSON property, together with attacker-controlled basePath and compressedFileName values, in a method=compress request. Because the application validates only domain ownership and does not canonicalize or restrict these paths to the authorized site directory, the backend appends them to zip or tar archive commands and executes them as the website externalApp user, allowing disclosure of arbitrary readable files through the generated archive.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79306"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-84713",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.7",
      "cwe": "CWE-639",
      "title": "Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-privilege cross-tenant recovery of notification recipient secrets via filter oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84713"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-84720",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-639",
      "title": "Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84720"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-86601",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Recipe Maker",
      "cwe": "CWE-74",
      "title": "WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86601"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-88837",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-305",
      "title": "Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88837"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-92164",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "streamlink",
      "product": "streamlink",
      "cwe": "CWE-73",
      "title": "Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92164"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-93529",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bilal Naseer",
      "product": "WSP MCP &#8211; AI Agents Connector",
      "cwe": "CWE-862",
      "title": "WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93529"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-93618",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetTricks",
      "cwe": "CWE-79",
      "title": "WordPress JetTricks plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93618"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-93620",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayPlus Tech Team",
      "product": "PayPlus Payment Gateway",
      "cwe": "CWE-862",
      "title": "WordPress PayPlus Payment Gateway plugin <= 8.2.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93620"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-93772",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-79",
      "title": "WordPress wpForo Forum plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93772"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-94118",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leap13",
      "product": "Premium Blocks – Gutenberg Blocks for WordPress",
      "cwe": "CWE-79",
      "title": "WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94118"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-94168",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leap13",
      "product": "Premium Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94168"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-94391",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rustaurius",
      "product": "Ultimate FAQ",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate FAQ plugin <= 2.4.14 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94391"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-94461",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metaphorcreations",
      "product": "Ditty",
      "cwe": "CWE-79",
      "title": "WordPress Ditty plugin <= 3.1.69 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94461"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-94498",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AppMySite",
      "product": "AppMySite",
      "cwe": "CWE-862",
      "title": "WordPress AppMySite plugin <= 3.15.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94498"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-94500",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roxnor",
      "product": "ElementsKit Elementor addons Lite",
      "cwe": "CWE-79",
      "title": "WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94500"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-94671",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "The Post Grid",
      "cwe": "CWE-79",
      "title": "WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94671"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-94680",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "The Post Grid",
      "cwe": "CWE-79",
      "title": "WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94680"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-94682",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SecondLineThemes",
      "product": "Podcast Importer SecondLine",
      "cwe": "CWE-79",
      "title": "WordPress Podcast Importer SecondLine plugin <= 1.5.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94682"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-94684",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oceanwp",
      "product": "Ocean Extra",
      "cwe": "CWE-79",
      "title": "WordPress Ocean Extra plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94684"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-95523",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP User Frontend",
      "cwe": "CWE-290",
      "title": "WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95523"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-95525",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP User Frontend",
      "cwe": "CWE-22",
      "title": "WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95525"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-95527",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Conekta Group",
      "product": "Conekta Payment Gateway",
      "cwe": "CWE-862",
      "title": "WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95527"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-95530",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PixelYourSite",
      "product": "PixelYourSite – Your smart PIXEL (TAG) Manager",
      "cwe": "CWE-79",
      "title": "WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95530"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-95586",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Ultimate Addons for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95586"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-95602",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITH",
      "product": "YITH WooCommerce Request A Quote",
      "cwe": "CWE-639",
      "title": "WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95602"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-63000",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "redaxo",
      "product": "core",
      "cwe": "CWE-352",
      "title": "REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63000"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-73586",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-613",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73586"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-84721",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.7",
      "cwe": "CWE-918",
      "title": "Automation-controller: automation-controller: email notification backend allows ssrf via user-controlled smtp host/port (internal port-scan oracle, smtp password exfil)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84721"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-59980",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-hyper",
      "product": "hpack",
      "cwe": "CWE-400",
      "title": "hpack: Unbounded variable integer decoding can cause run-away computation on malformed input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59980"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-73589",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-261",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73589"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-92700",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-178",
      "title": "Caddy: fileHidden() case-sensitive pattern bypass — exposes \"hidden\" files via case variation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92700"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-96456",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pollen Robotics",
      "product": "Reachy Mini",
      "cwe": "CWE-287",
      "title": "Reachy Mini Bluetooth PIN authentication can be bypassed by racing an authenticated device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96456"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-6718",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-276",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6718"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-19267",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-306",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19267"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-88835",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-125",
      "title": "Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88835"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-63131",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbao",
      "product": "openbao",
      "cwe": "CWE-863",
      "title": "OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63131"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-66067",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: Stream protocol skips per vhost per user connection limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66067"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-66072",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: Atom table exhaustion via stream `chunk_selector`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66072"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-66074",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-1333",
      "title": "RabbitMQ: ReDoS via management API ?name= filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66074"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-67219",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: Consistent-hash exchange unbounded weight",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67219"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-67220",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-400",
      "title": "RabbitMQ: JMS topic exchange erl_scan atom exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67220"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-5696",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microweber",
      "product": "Administration panel",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in the Microweber administration panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5696"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-6669",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PgBouncer",
      "cwe": "CWE-400",
      "title": "Unbounded SCRAM iteration count causes CPU exhaustion in PgBouncer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6669"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-66080",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: Super-stream partitions unbounded allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66080"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-67221",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-312",
      "title": "RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67221"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-66068",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-532",
      "title": "RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66068"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-86612",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ninja Tables",
      "cwe": "CWE-74",
      "title": "Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86612"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-77420",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jline",
      "product": "jline3",
      "cwe": "CWE-1333",
      "title": "JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77420"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-96513",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Neethuharii",
      "product": "CafeManagement",
      "cwe": "CWE-284",
      "title": "Neethuharii CafeManagement AddProductCode.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96513"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-96514",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Neethuharii",
      "product": "CafeManagement",
      "cwe": "CWE-74",
      "title": "Neethuharii CafeManagement Login CafePortalLogin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96514"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-96556",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Neethuharii",
      "product": "CafeManagement",
      "cwe": "CWE-266",
      "title": "Neethuharii CafeManagement AddCashierCode.php addcashier improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96556"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-96601",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Abdurrab5",
      "product": "online-makeup-store",
      "cwe": "CWE-74",
      "title": "Abdurrab5 online-makeup-store Admin Login index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96601"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-96602",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Abdurrab5",
      "product": "online-makeup-store",
      "cwe": "CWE-74",
      "title": "Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96602"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-96603",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Abdurrab5",
      "product": "online-makeup-store",
      "cwe": "CWE-862",
      "title": "Abdurrab5 online-makeup-store Admin functions.php confirm_user authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96603"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-96604",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SoftNews Media Group",
      "product": "DataLife Engine",
      "cwe": "CWE-74",
      "title": "SoftNews Media Group DataLife Engine Search search.php strip_data sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96604"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-96606",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LB-Link",
      "product": "BL-CPE600EU",
      "cwe": "CWE-200",
      "title": "LB-Link BL-CPE600EU Configuration Backup Mifi_config.bin information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96606"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-18505",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-601",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18505"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-71177",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-1021",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71177"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-80444",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Abis Technology Ltd. Co.",
      "product": "AVESİS",
      "cwe": "CWE-601",
      "title": "Unauthenticated Open Redirect Vulnerability in Abis Technology's AVESİS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80444"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-88974",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-graphql",
      "product": "wp-graphql",
      "cwe": "CWE-863",
      "title": "WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88974"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-92874",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92874"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-94679",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Fluent Support",
      "cwe": "CWE-862",
      "title": "WordPress Fluent Support plugin <= 2.3.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94679"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-3626",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-209",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3626"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-6925",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-22",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6925"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-52744",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-862",
      "title": "GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52744"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-67405",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-1385",
      "title": "RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67405"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-73858",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "solspace",
      "product": "craft-freeform",
      "cwe": "CWE-1336",
      "title": "Solspace Freeform: Limited Twig template injection via submitted field values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73858"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-84091",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SUMIT Payment Gateway for WooCommerce",
      "cwe": "CWE-287",
      "title": "SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84091"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-84712",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-497",
      "title": "Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84712"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-84717",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-204",
      "title": "Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84717"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-87070",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Forminator Forms",
      "cwe": "CWE-348",
      "title": "Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87070"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-87071",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Forminator Forms",
      "cwe": "CWE-20",
      "title": "Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87071"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-87978",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paymob for WooCommerce",
      "cwe": "CWE-345",
      "title": "Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87978"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-88831",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-636",
      "title": "Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88831"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-88840",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-125",
      "title": "Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88840"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-90900",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90900"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-90950",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paid Membership Subscriptions",
      "cwe": "CWE-693",
      "title": "Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90950"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-92419",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WEBCON",
      "product": "WEBCON BPS",
      "cwe": "CWE-639",
      "title": "IDOR in WEBCON BPS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92419"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-93421",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mesop-dev",
      "product": "mesop",
      "cwe": "CWE-117",
      "title": "Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93421"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-93623",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jordy Meow",
      "product": "AI Engine",
      "cwe": "CWE-639",
      "title": "WordPress AI Engine plugin <= 3.7.8 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93623"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-94079",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP User Manager",
      "product": "WP User Manager",
      "cwe": "CWE-862",
      "title": "WordPress WP User Manager plugin <= 2.9.19 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94079"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-94080",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebWizards",
      "product": "MarketKing",
      "cwe": "CWE-862",
      "title": "WordPress MarketKing plugin <= 2.1.70 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94080"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-95514",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netgsm",
      "product": "Netgsm",
      "cwe": "CWE-289",
      "title": "WordPress Netgsm plugin <= 2.10.0 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95514"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-95524",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP User Frontend",
      "cwe": "CWE-290",
      "title": "WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95524"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-95592",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oleh RadiusTheme",
      "product": "Team",
      "cwe": "CWE-639",
      "title": "WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95592"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-95600",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TrustedLogin",
      "product": "TrustedLogin Connector",
      "cwe": "CWE-497",
      "title": "WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95600"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-96652",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plex",
      "product": "Media Server",
      "cwe": "CWE-918",
      "title": "Plex Media Server SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96652"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-96655",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plex",
      "product": "Media Server",
      "cwe": "CWE-918",
      "title": "Plex Media Server arbitrary-host SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96655"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-96672",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "ERPNext",
      "cwe": "CWE-470",
      "title": "Frappe ERPNext before 16.34.1 Unauthorized Method Invocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96672"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-96739",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SEMCMS",
      "cwe": "CWE-79",
      "title": "SEMCMS KindEditor Upload upload_json.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96739"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-71458",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-204",
      "title": "Automation-controller: automation-controller-container: automation-controller: named-url 404 body oracle enables cross-tenant resource name enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71458"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-71459",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-862",
      "title": "Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary rbac bypass exposes cross-tenant job event tree structure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71459"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-63001",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "redaxo",
      "product": "core",
      "cwe": "CWE-79",
      "title": "REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63001"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-63002",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "redaxo",
      "product": "core",
      "cwe": "CWE-79",
      "title": "REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63002"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-86604",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GTranslate",
      "cwe": "CWE-74",
      "title": "GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86604"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-94457",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebFactory",
      "product": "Captcha Code",
      "cwe": "CWE-290",
      "title": "WordPress Captcha Code plugin <= 3.32 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94457"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-96674",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ALSA Project",
      "product": "alsa-lib",
      "cwe": "CWE-190",
      "title": "alsa-lib through 1.2.16.1 Integer Overflow via Topology File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96674"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-96675",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ALSA Project",
      "product": "alsa-lib",
      "cwe": "CWE-129",
      "title": "alsa-lib through 1.2.16.1 Denial of Service via pcm_multi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96675"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-19087",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager (FTM) for RedHat OpenShift",
      "cwe": "CWE-250",
      "title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19087"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-96545",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96545"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-6327",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-117",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6327"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-55632",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gocd",
      "product": "gocd",
      "cwe": "CWE-863",
      "title": "GoCD is vulnerable to authorization bypass via pipeline structure API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55632"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-61834",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thomaspoignant",
      "product": "scim-patch",
      "cwe": "CWE-915",
      "title": "scim-patch: Mutation of Inherited Built-in Method Objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61834"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-62998",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "redaxo",
      "product": "core",
      "cwe": "CWE-20",
      "title": "REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62998"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-71460",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-862",
      "title": "Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subscription/license details via /config/",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71460"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-71461",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.7",
      "cwe": "CWE-209",
      "title": "Automation-controller: automation-controller-container: automation-controller: verbose internal exception disclosure via hostlist bare-exception handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71461"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-84718",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-348",
      "title": "Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84718"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-92529",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92529"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-92530",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-348",
      "title": "Use of Less Trusted Source in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92530"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-93513",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SiteSkite",
      "product": "SiteSkite",
      "cwe": "CWE-639",
      "title": "WordPress SiteSkite plugin <= 2.1.7 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93513"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-96446",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96446"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-71462",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-204",
      "title": "Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesystem path-existence oracle on control pod",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71462"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-96807",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flatpak",
      "product": "Flatpak",
      "cwe": "CWE-61",
      "title": "In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96807"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-71178",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Secure Connect Gateway (SCG) Policy Manager",
      "cwe": "CWE-647",
      "title": "Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71178"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-77756",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-444",
      "title": "Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77756"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-87848",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MPCX Lightbox",
      "cwe": "CWE-862",
      "title": "MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87848"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-71464",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-88",
      "title": "Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_branch prompt bypasses leading-dash git-argument guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71464"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-71465",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-88",
      "title": "Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli argument injection into ansible executable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71465"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-92628",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-362",
      "title": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92628"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-96548",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-259",
      "title": "sfturing hosp_order jdbc.properties hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96548"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-96550",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-310",
      "title": "sfturing hosp_order MailUtil.java getProperties cleartext transmission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96550"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-96872",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - WikiLambda Extension",
      "cwe": "CWE-280",
      "title": "WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96872"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-4921",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-209",
      "title": "IBM Guardium Data Protection is affected by multiple vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4921"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-71463",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-209",
      "title": "Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist bypass via conditional gating leaks tracebacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71463"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-96546",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96546"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-77285",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbao",
      "product": "openbao",
      "cwe": "CWE-532",
      "title": "OpenBao Agent Writes Secrets to Stdout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77285"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-66069",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66069"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-66075",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Monitoring-tag user can restart federation links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66075"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-66076",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66076"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-67240",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-1333",
      "title": "RabbitMQ: ReDoS via AMQP 1.0 SQL filter LIKE wildcard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67240"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-78253",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "qt",
      "cwe": "CWE-674",
      "title": "Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78253"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-67218",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Super-stream HTTP creation skips configure-permission check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67218"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-67224",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-22",
      "title": "RabbitMQ: Admin path-traversal write via trace name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67224"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-96551",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-352",
      "title": "sfturing hosp_order CommonUserController.java cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96551"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-96676",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fast",
      "product": "FAC1900R",
      "cwe": "CWE-119",
      "title": "Fast FAC1900R uhttpd get_alias_name stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96676"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-96678",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weiqingwen",
      "product": "spring-boot-forum",
      "cwe": "CWE-22",
      "title": "weiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96678"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-96680",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ByteDance",
      "product": "Coze Scraper Extension",
      "cwe": "CWE-862",
      "title": "ByteDance Coze Scraper Extension External Message index.js chrome.runtime.onMessageExternal.addListener authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96680"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-96549",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-310",
      "title": "sfturing hosp_order CommonUserServiceImpl.java cleartext storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96549"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-96552",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sfturing",
      "product": "hosp_order",
      "cwe": "CWE-325",
      "title": "sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96552"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-82356",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imprivata",
      "product": "Imprivata Enterprise Access Management",
      "cwe": null,
      "title": "Imprivata EAM: Unrotatable X.509 RSA Key Pair in Production",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82356"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-86867",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cinnamon AI",
      "product": "Kotaemon",
      "cwe": null,
      "title": "Cinnamon's kotaemon contains improper authorization checks in multi‑user chat handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86867"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-86926",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Claris",
      "product": "FileMaker Server",
      "cwe": null,
      "title": "A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86926"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-86930",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Claris",
      "product": "FileMaker Server",
      "cwe": null,
      "title": "An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86930"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-86934",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Claris",
      "product": "FileMaker Server",
      "cwe": null,
      "title": "An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86934"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-86938",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Claris",
      "product": "FileMaker Pro",
      "cwe": null,
      "title": "A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86938"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25104",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25104 (MediaArea MediaInfoLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25713",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25713 (MediaArea MediaInfoLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26824",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26824. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26825",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26825. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28764 (MediaArea MediaInfoLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43641",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43641 (Softaculous Virtualizor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47116",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47116 (LTSecurity LTK3500SF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56818",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56818 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67615",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67615 (Apereo Foundation openEQUELLA). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77006",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77006 (Unknown WebTotem Backups). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85706",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85706 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87719",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87719 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92764 (opencve). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93307",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93307 (O-RAN-SC SMO OAM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93533",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93533 (spatie Scotty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93739",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93739 (Totolink A3002MU). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94109",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94109 (openEQUELLA). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94536",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94536 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95812 (MacWarrior clipbucket-v5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95819",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95819 (anirbandutta9 College-Notes-Gallery). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95820",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95820 (anirbandutta9 College-Notes-Gallery). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-95828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-95828 (Mstfakts College-Management-System). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-81963",
      "detail": "DUE DATE PASSED — CVE-2026-81963 (Microsoft Windows 11 version 23H2). CISA remediation deadline was September 22, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-85880",
      "detail": "DUE DATE PASSED — CVE-2026-85880 (Microsoft Windows 10 Version 1607). CISA remediation deadline was September 22, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10027",
      "detail": "RESCORED — CVE-2026-10027 (IBM MQ). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10853",
      "detail": "RESCORED — CVE-2026-10853 (IBM MQ). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12749",
      "detail": "RESCORED — CVE-2026-12749 (IBM Cloud Pak for Business Automation). CVSS 6.4 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12750",
      "detail": "RESCORED — CVE-2026-12750 (IBM Cloud Pak for Business Automation). CVSS 6.4 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-13745",
      "detail": "RESCORED — CVE-2026-13745 (Google Cloud Gemini CLI). CVSS 9.2 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47116",
      "detail": "RESCORED — CVE-2026-47116 (LTSecurity LTK3500SF). CVSS 9.3 → 9.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59302",
      "detail": "RESCORED — CVE-2026-59302 (Spring Cloud Stream). CVSS 3.1 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-59903",
      "detail": "RESCORED — CVE-2026-59903 (netty). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69512",
      "detail": "RESCORED — CVE-2026-69512 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-72927",
      "detail": "RESCORED — CVE-2026-72927 (Microsoft Windows 10 Version 1607). CVSS 6.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-73508",
      "detail": "RESCORED — CVE-2026-73508 (netty). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78552",
      "detail": "RESCORED — CVE-2026-78552 (Okta Access Gateway). CVSS 6 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78560",
      "detail": "RESCORED — CVE-2026-78560 (Okta Access Gateway). CVSS 4.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78574",
      "detail": "RESCORED — CVE-2026-78574 (Okta Hyperdrive Integration Plugin). CVSS 7.5 → 6.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-78579",
      "detail": "RESCORED — CVE-2026-78579 (Okta Access Gateway). CVSS 6.8 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80225",
      "detail": "RESCORED — CVE-2026-80225 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81352",
      "detail": "RESCORED — CVE-2026-81352 (Microsoft Web Media Extensions). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81355",
      "detail": "RESCORED — CVE-2026-81355 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-81380",
      "detail": "RESCORED — CVE-2026-81380 (Microsoft Visual Studio Code). CVSS 5.3 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-82443",
      "detail": "RESCORED — CVE-2026-82443 (Adobe Campaign Classic). CVSS 9.6 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-83660",
      "detail": "RESCORED — CVE-2026-83660 (Adobe Campaign Classic). CVSS 9.9 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-85501",
      "detail": "RESCORED — CVE-2026-85501 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-88013",
      "detail": "RESCORED — CVE-2026-88013 (rclone). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-95829",
      "detail": "RESCORED — CVE-2026-95829 (TDuckCloud tduck-platform). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-95830",
      "detail": "RESCORED — CVE-2026-95830 (theRealSain Pixtream). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-95833",
      "detail": "RESCORED — CVE-2026-95833 (itsourcecode Leave Management System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2025-11395",
      "detail": "PATCH SHIPPED — CVE-2025-11395 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:1.43.3-2.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-11861",
      "detail": "PATCH SHIPPED — CVE-2026-11861 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-13097",
      "detail": "PATCH SHIPPED — CVE-2026-13097 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18147",
      "detail": "PATCH SHIPPED — CVE-2026-18147 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-19550",
      "detail": "PATCH SHIPPED — CVE-2026-19550 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-28183",
      "detail": "PATCH SHIPPED — CVE-2026-28183 (PublishPress Capabilities). Fixed in PublishPress Capabilities 2.50.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-73197",
      "detail": "PATCH SHIPPED — CVE-2026-73197 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-73198",
      "detail": "PATCH SHIPPED — CVE-2026-73198 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-76578",
      "detail": "PATCH SHIPPED — CVE-2026-76578 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-79678",
      "detail": "PATCH SHIPPED — CVE-2026-79678 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-84470",
      "detail": "PATCH SHIPPED — CVE-2026-84470 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.33-1.el8ap."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-93337",
      "detail": "PATCH SHIPPED — CVE-2026-93337 (nm-l2tp NetworkManager-l2tp). Fixed in NetworkManager-l2tp 1.52.6."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
